Repository navigation
fix(template): a health check path is optional, and draft and info show it - #358
Conversation
…ow it The platform stopped requiring a health check path on a web service in #600, but the local manifest check still refused a web service without one, and it accepted any given path that began with a slash. A web service may now omit the path, and a given path is checked with the platform's HEALTHCHECK_RE, so //host is refused here as the platform refuses it. A declared empty or non-string path stays refused, and so does any health check on a worker. insta template draft and insta template info now print a web service's health check in their human output: health check /healthz, or no health check. A worker or a managed service prints nothing about it. --json is unchanged.
The path grammar check also ran on a worker, so a worker with a health check such as //x got the worker refusal plus a second line telling the author to fix a path they should remove. The grammar check now skips a worker, so it only gets the refusal.
jwfing
left a comment
There was a problem hiding this comment.
Summary
The implementation correctly makes web health checks optional, validates declared paths, and exposes health-check status in human-readable draft/info output.
Requirements context
I assessed the change against the PR description and the validator’s documented contract to mirror platform validation (src/template-manifest.ts:1-6). The linked platform PR and superproject design note were not present or accessible from this checkout. No command or flag changes require a CLI-reference update.
Findings
Critical
(none)
Suggestion
(none)
Information
- Software engineering / functionality: The validator distinguishes omission from invalid declared values, applies the stated path grammar, and prevents duplicate errors for workers (
src/template-manifest.ts:154-164). Regression tests cover omitted, valid, relative, protocol-relative, empty, non-string, and worker values (test/template.test.ts:230-267). - Human-readable draft and info rendering is restricted to web services and covers paths, absent values, legacy missing fields, workers, and managed services (
src/commands/template-author.ts:96-110,src/commands/template.ts:110-121,test/template-author.test.ts:193-211,test/template.test.ts:469-489). Existing JSON pass-through behavior remains covered (test/template-author.test.ts:187-191). - Security: No new authorization, secret, SQL, shell, or dependency surface is introduced. The stricter grammar rejects protocol-relative URLs, schemes, backslashes, spaces, fragments, and control characters (
src/template-manifest.ts:68-69,src/template-manifest.ts:160-164). - Performance: No performance-relevant concern; the change adds one bounded regular-expression check per declared health check and constant work per rendered service (
src/template-manifest.ts:160-164,src/commands/template.ts:110-121).
Verdict
Approved under the supplied rubric: zero Critical findings. git diff --check passes; tests and typecheck could not be executed locally because this checkout has no installed vitest or tsc dependencies.
## What Version bump for v0.1.23. Since v0.1.22: - #360: a lock's release can no longer delete a lock taken over during it, and the contention test models abandonment as the holder exiting. - #358: a template's health check path is optional, and `template draft` and `template info` show it. InsForge/instacloud-platform#641, which accepts an empty path as none, is in production. - #362: `template drafts --json` prints one summary per template, and its help says so. InsForge/instacloud-platform#650, which serves the summary rows, is in production (08bc4324). ## How `package.json` and `package-lock.json` move from 0.1.22 to 0.1.23, nothing else. ## Verify - The three changes above merged with green Linux and Windows CI, and main's CI is green after each. - After merge the tag `v0.1.23` on main runs the release workflow (binaries and npm). `npm view insta version` should print 0.1.23. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
What
A template's health check path is optional, as the platform has allowed since InsForge/instacloud-platform#600. The CLI still refused a web service without one, so a template the platform accepts was refused locally.
insta template deploy <dir>and the GitHub URL mode accept a web service without ahealthcheck. A given path is checked with the platform's own grammar, so//hostis refused locally as the platform refuses it.insta template draftandinsta template infoprint each web service's health check:health check /healthz, orno health check. A worker or a managed service prints nothing about it.--jsonis unchanged.How
src/template-manifest.ts: the "web services must declare a healthcheck path" rule is gone.HEALTHCHECK_REmirrors the platform's (src/provisioning/templateManifest.ts, same constant). A declared empty or null path is still refused locally, as the platform refuses it. A worker with any path gets only the worker refusal.src/commands/template-author.tsandsrc/commands/template.ts: the health check on a web service's line.Verify
npm run typecheckandnpm test: 102 files, 2112 tests.//evil.example,http://x/y, an empty and a null path are refused. A worker with/healthz,//x,health, an empty or a null path yields exactly one problem, the worker refusal. The draft and info lines for a web service with and without a path, a worker and a managed service.Design note (insta-cloud superproject, branch
spec/community-templates): template health check alignment. Companion PRs: the oss lint and daemon, the insta skill, and a platform fix for empty settings.🤖 Generated with Claude Code
Summary by cubic
Makes a web service's health check path optional in local template validation, matching the platform's behavior since InsForge/instacloud-platform#600.
The CLI no longer refuses a web service without a
healthcheckpath, and a given path is checked against the platform's own grammar, so//hostis refused locally just as the platform refuses it. Empty, null, or non-string paths stay refused, and a worker with any health check gets only the worker refusal, not a second path error.insta template draftandinsta template infonow print each web service's health check—health check /healthzorno health check—while workers and managed services print nothing about it.--jsonoutput is unchanged.Written for commit 524ab67. Summary will update on new commits.