Repository navigation
feat(health): add dependency-aware readiness and recovery diagnostics - #140
Open
woahwhattheheck wants to merge 9 commits into
Open
woahwhattheheck wants to merge 9 commits into
woahwhattheheck wants to merge 9 commits into
Conversation
Separate process liveness from traffic readiness. Ready probes now check store, payments (Stellar), and FX under a per-dependency timeout, return redacted reason codes on failure, and re-evaluate every request so recovery does not require a restart. Liveness stays dependency-free so outages do not flap orchestrator restarts. Closes RemitFlow#134
Validate the actual loaded rate values for every advertised currency so a missing or corrupt FX table cannot report ready while rate requests fail. Keep the existing success payload, FX_UNAVAILABLE code and corridors. Exercise table loss, liveness and same-process recovery through the actual HTTP app, plus partial invalid-rate states. The new data-loss regression failed against the previous source with 200 instead of 503. Validation: npm test passed all 271 tests; no tests skipped.
Serve only GET/HEAD liveness before the global API budget, preserving common middleware and the existing health controller. Readiness, business traffic and unmatched routes stay limited. Native createApp before/after: 17 local HTTP requests per phase prove availability after quota exhaustion and that liveness polls do not spend the business budget. Existing FX outage/recovery behavior is preserved. All 273 tests from the unchanged npm test selection pass on Node 24.19.0 with --test-concurrency=1 and retained packages matching all 76 lockfile versions. Focused health checks: 17 pass; exact parent with identical final tests: 2 fail / 15 pass. Syntax and whitespace checks pass. CI uses Node 22 and remains a separate hosted gate; services retain their in-memory/mock boundary.
Author
|
Current-head QA at |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes #134.
Separates process liveness from traffic readiness and adds bounded, redacted dependency probes so a process can no longer report healthy while its store, payment provider, or FX dependency is down.
Current behavior
GET /api/health/liveis process-only and dependency-free, and is routed ahead of the business API rate limiter so dependency outages or exhausted business quotas do not make the liveness probe flap.GET /api/health/readyprobesstore, payments (Stellar), and FX under a normalized per-check deadline (HEALTH_CHECK_TIMEOUT_MS, default 1000ms).STORE_UNAVAILABLEandPAYMENTS_TIMEOUT; raw provider messages, stacks, credentials, and connection strings are not returned.Design boundaries
/api/health/readyremains behind the normal API middleware/rate-limit path; only liveness bypasses the business quota.Acceptance mapping
/api/health/livepath, ahead of business quotanot_readywhile liveness remains availableValidation boundary
Exact current head:
364882b6ace3336480f7a358eb20283bdc61a40d(9 commits / 17 files).Historical focused evidence retained in-repo:
b4c9505ee1ac758ebb3fff659bbe39747febaa6b: 29 focused tests passed in run 37193635966, including repeated timeout sharing and recoverydocs/READINESS_TIMER_RANGE.mdThe current exact head also adds dependency-scoped reason-code coverage. Its hosted CI run 37211797983 is
action_required; there are no current-head status contexts or review submissions. Therefore this PR does not claim a fresh current-head full-suite or CI-green result.Compatibility
/api/healthand/api/health/livekeep their existing process-health semantics./api/health/readyexposes structured per-dependency entries (status,latencyMs, optionalreason) plus the effective timeout budget.