diff --git a/content/configuration/healthcheck.md b/content/configuration/healthcheck.md index 2c3b390b..9908a2ea 100644 --- a/content/configuration/healthcheck.md +++ b/content/configuration/healthcheck.md @@ -6,7 +6,9 @@ description: Configuration for the server health check service. :partial{content="config-env-vars"} -The health check service powers the `/server/health` endpoint, which reports the status of connected services like the database, edis, storage, and email. Results are cached and shared across requests to avoid excessive checks. +The health check service powers the `/server/health` endpoint, which reports the status of connected services like the database, Redis, storage, and email. Results are cached and shared across requests to avoid excessive checks. In multi-instance deployments, the cached result is shared across all instances. + +The endpoint requires authentication. Unauthenticated requests receive a `403` error, non-admin users receive only the overall `status`, and admin users receive the result of each individual check. For unauthenticated liveness checks, use `/server/ping` instead. See [Health Checks](/self-hosting/deploying#health-checks) for details. | Variable | Description | Default Value | | ----------------------- | ----------------------------------------------------------------------------------------------------- | ------------------------------ | diff --git a/content/releases/3.breaking-changes/3.version-12.md b/content/releases/3.breaking-changes/3.version-12.md index 78fb1e45..b5fe8ccc 100644 --- a/content/releases/3.breaking-changes/3.version-12.md +++ b/content/releases/3.breaking-changes/3.version-12.md @@ -126,6 +126,8 @@ If you style or process stored HTML by tag, class, or attribute, review affected This option passed raw TinyMCE configuration to the editor and no longer has any effect. Existing values are ignored and log a deprecation warning in the browser console, and the option is hidden for new fields. It will be removed in a future release. Configure the toolbar, custom formats, font families, and font sizes through the interface's dedicated options instead. +TinyMCE is no longer bundled with the Data Studio. Custom TinyMCE plugins, skins, and content CSS no longer apply, and the global `tinymce` object is no longer available to extensions. + ### App Access policies read a limited set of settings fields The minimal permissions attached to a policy with **App Access** enabled previously granted read access to every field on `directus_settings`, including admin-only configuration and AI provider credentials. New policies now grant read access to only the fields a non-admin user needs: @@ -207,6 +209,8 @@ See [Hardened Images](/self-hosting/hardened-images) for details on both images, Jump to: - [License Enforcement](#license-enforcement) +- [`IP_TRUST_PROXY` Default Changed to `false`](#ip_trust_proxy-default-changed-to-false) +- [`/server/health` Requires Authentication](#serverhealth-requires-authentication) - [Draft Publishing Workflow](#draft-publishing-workflow) - [Extension Compatibility](#extension-compatibility) @@ -253,6 +257,21 @@ No data is deleted as a result of enforcement — access is restricted via deact The `IP_TRUST_PROXY` default has been changed from `true` to `false`. If you run Directus behind a reverse proxy and rely on `X-Forwarded-For` (or similar) headers for client IP resolution, you must now explicitly set `IP_TRUST_PROXY` to `true` or a more specific trust configuration. +### `/server/health` Requires Authentication + +Unauthenticated requests to `/server/health` now fail with a `403` `FORBIDDEN` error. Previously, the endpoint returned the overall health status to anyone. Load balancer probes, uptime monitors, and container health checks that call `/server/health` without a token will fail after upgrading, which can mark the instance as unhealthy or trigger an automatic rollback. + +Update each health check based on what it needs to verify: + +- **Liveness** - switch to `/server/ping`. It stays public and returns `pong` once the HTTP server is running. It does not check the database, Redis, storage, or email. +- **Dependency status** - keep `/server/health` and send an access token with the request, for example a [static token](/guides/auth/tokens-cookies#static-tokens) for a dedicated user. Non-admin users receive only the overall `status`. Admin users receive the full report, including individual checks. + +The health check service has also changed in the following ways: + +- Results are cached for [`HEALTHCHECK_CACHE_TTL`](/configuration/healthcheck) (default `5m`) and shared across instances in multi-instance deployments. A reported status can lag behind the real state of a dependency by up to this duration. +- The `cache`, `rateLimiter`, and `rateLimiterGlobal` checks have been replaced by a single `redis` check, reported under the `redis:` prefix. Update any monitoring that reads individual check names. +- [`HEALTHCHECK_ENABLED`](/configuration/healthcheck) and `HEALTHCHECK_SERVICES` let you disable the endpoint or limit which services it checks. + ### Draft Publishing Workflow #### Published items in versioned collections are now locked from direct editing diff --git a/content/self-hosting/3.deploying.md b/content/self-hosting/3.deploying.md index 3e753019..7fee5940 100644 --- a/content/self-hosting/3.deploying.md +++ b/content/self-hosting/3.deploying.md @@ -124,5 +124,7 @@ The Docker Compose example above includes health checks for all services. If you Directus exposes two endpoints for health monitoring: -- `/server/health` - returns detailed health status including database and cache connectivity. Returns a `503` if any dependency is unhealthy (for example, a missing email transport configuration). This is a resource intensive call so we recommend to only use when you need an actual check of the dependencies like the database, cache, email transport, etc. -- `/server/ping` - returns `pong` if the HTTP server is running, regardless of dependency status. Use this for basic health checks. +- `/server/ping` - returns `pong` if the HTTP server is running, regardless of dependency status. It does not require authentication. Use this for liveness checks, load balancer probes, and container health checks. +- `/server/health` - returns the health status of dependencies such as the database, Redis, storage, and email. Returns a `503` if any dependency is unhealthy (for example, a missing email transport configuration). Use this only when you need to verify dependencies, as checking them is resource intensive. + +`/server/health` requires authentication and returns a `403` for unauthenticated requests. Non-admin users receive only the overall `status`, while admin users receive the result of each individual check. To call it from a monitoring tool, create a dedicated user and send its [static token](/guides/auth/tokens-cookies#static-tokens) with each request. See [Health Check](/configuration/healthcheck) for caching and configuration options.