fix(deploy): healthcheck must hit the real host IP, not localhost
CI / Repo hygiene (pull_request) Successful in 1s
CI / Web (lint, typecheck, build) (pull_request) Successful in 15s
CI / Migrations reversible (pull_request) Successful in 9s
CI / API (lint, types, tests) (pull_request) Successful in 54s

The deploy job runs inside its own ephemeral DooD job container, which is a
separate container from `caddy` — caddy's -p 8090:80 publishes onto the real
host's network namespace, not this job container's own loopback. A
`localhost:8090` curl here would fail with connection-refused regardless of
whether the deploy actually succeeded, misreporting a working deploy as a
failed workflow. Point it at the same host IP deploy/.env.example's
VELODROME_PUBLIC_URL already uses.

Caught during review, not left as the open caveat the PR description flagged
it as.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-21 15:11:33 -04:00
co-authored by Claude Opus 5
parent 5d4d76203f
commit 4f4ca345ca
+6 -1
View File
@@ -110,10 +110,15 @@ jobs:
docker compose --env-file "$ENV_FILE" up -d
- name: Wait for the API to become healthy
# NOT localhost: this step runs inside the runner's own ephemeral DooD job container,
# which is a separate container from `caddy` — `caddy`'s -p 8090:80 publishes onto the
# real host's network namespace, not this job container's loopback, so `localhost:8090`
# here would just be connection-refused regardless of whether the deploy actually
# succeeded. Hit the same host IP deploy/.env.example's VELODROME_PUBLIC_URL already uses.
run: |
set -euo pipefail
for i in $(seq 1 10); do
if curl -fsS http://localhost:8090/api/v1/healthz; then
if curl -fsS http://192.168.0.103:8090/api/v1/healthz; then
echo "Healthy."
exit 0
fi