Make fresh router startup reliable
This commit is contained in:
1 parent
868b89be1d
commit
bea144c91e
2 files changed
+26
-4
No files matched your search
+12
-3
@@ -323,8 +323,15 @@ services:
|
||||
cap_drop: [ALL]
|
||||
# The entrypoint fixes ownership of fresh named volumes and immediately
|
||||
# drops to uid/gid 10002 via gosu before starting the router. Without this
|
||||
# narrowly scoped capability a clean installation loops before startup.
|
||||
cap_add: [CHOWN]
|
||||
# narrowly scoped capabilities a clean installation cannot initialize the
|
||||
# volumes and then switch to its unprivileged runtime identity.
|
||||
cap_add: [CHOWN, SETUID, SETGID]
|
||||
healthcheck:
|
||||
test: [CMD, python, -c, "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8081/health', timeout=2)"]
|
||||
interval: 5s
|
||||
timeout: 3s
|
||||
retries: 24
|
||||
start_period: 5s
|
||||
depends_on:
|
||||
profile-controller:
|
||||
condition: service_healthy
|
||||
@@ -351,7 +358,9 @@ services:
|
||||
- "${AI_BIND_ADDRESS:-127.0.0.1}:8080:8080"
|
||||
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||
networks: [frontend, tools]
|
||||
depends_on: [router]
|
||||
depends_on:
|
||||
router:
|
||||
condition: service_healthy
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
|
||||
networks:
|
||||
|
||||
Reference in new issue
Block a user