Skip to content

ref(healthcheck): Share one python3 HTTP healthcheck for sentry web and snuba api - #4539

Merged
oioki merged 3 commits into
masterfrom
alextarasov/shared-http-healthcheck
Sep 30, 2026
Merged

oioki merged 3 commits into
masterfrom
alextarasov/shared-http-healthcheck

Conversation

@oioki

@oioki oioki commented Sep 30, 2026 •

Copy link
Copy Markdown
Member

Replace the web healthcheck's bash /dev/tcp probe with healthcheck/check_http.py, and use the same script for snuba-api. It's snuba/api_healthcheck.py generalized to take the URL as an argument: stdlib only, one-line errors, 2s timeout.

The new healthcheck/ directory is mounted read-only at /healthcheck (like ./geoip) through x-sentry-defaults and on snuba-api, rather than putting a script into the ./sentry config mount. The SNUBA_API_HEALTHCHECK_URL/_TIMEOUT overrides are gone; override the whole test: in docker-compose.override.yml instead.

web still checks the plain /_health/, not ?full, so a down dependency doesn't mark web unhealthy and block everything that depends on it.

Prep for moving the sentry image to a distroless base, which has no bash.

…nd snuba api

Replace the web healthcheck's bash /dev/tcp probe, which needs a shell, with healthcheck/http.py, a generalized version of snuba/api_healthcheck.py that takes the URL as an argument. The healthcheck/ directory is mounted read-only at /healthcheck, like ./geoip, for sentry services and snuba-api.
@oioki
oioki marked this pull request as ready for review September 30, 2026 09:00
@oioki
oioki requested review from aldy505 and aminvakil September 30, 2026 09:00
@oioki
oioki marked this pull request as draft September 30, 2026 09:11
… package

Running python3 /healthcheck/http.py puts /healthcheck first on sys.path, so urllib's 'import http.client' picked up the script instead of the standard library and every healthcheck failed.
@github-actions

github-actions Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Coverage Results 📊

✅ 22 passed | Total: 22 | Pass Rate: 100% | Execution Time: 10m 41s

All tests are passing successfully.

✅ Patch coverage is 100.00% (no changed executable lines found; target 50%).
Project statement coverage is 95.54% (unchanged from base (49e367f) to head (8f96168)).

Coverage diff
@@            Coverage Diff             @@
##        master     #4539       +/-##
==========================================
  Coverage    95.54%    95.54%        —%
==========================================
  Files            5         5         —
  Tracked lines       336       336         —
  Branches         0         0         —
==========================================
  Hits           321       321         —
  Misses          15        15         —
  Partials         0         0         —

Generated by Coverage Action

@oioki
oioki marked this pull request as ready for review September 30, 2026 09:44

@BYK BYK left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice. I'd have preferred if this file was baked into the image but this is also nice.

Docker can inject HTTP_PROXY/http_proxy into containers from the client config, and urllib would then send the local health request through the proxy. The target is always the container itself, so bypass proxies, like the clickhouse and seaweedfs healthchecks already do.
@oioki
oioki merged commit 9086cbb into master Sep 30, 2026
23 checks passed
@oioki
oioki deleted the alextarasov/shared-http-healthcheck branch September 30, 2026 18:52
@oioki

oioki commented Sep 30, 2026

Copy link
Copy Markdown
Member Author
Sanity check: healthcheck status right after container starts (sentry and snuba)
dogfood@dogfood:~/self-hosted$ docker inspect --format '{{json .State.Health}}' sentry-self-hosted-web-1 | jq .
{
  "Status": "healthy",
  "FailingStreak": 0,
  "Log": [
    {
      "Start": "2026-09-30T12:04:39.877752308-07:00",
      "End": "2026-09-30T12:04:42.511553338-07:00",
      "ExitCode": 1,
      "Output": "http://127.0.0.1:9000/_health/ unreachable: [Errno 111] Connection refused\n"
    },
    {
      "Start": "2026-09-30T12:04:47.513712017-07:00",
      "End": "2026-09-30T12:04:49.904815931-07:00",
      "ExitCode": 1,
      "Output": "http://127.0.0.1:9000/_health/ unreachable: [Errno 111] Connection refused\n"
    },
    {
      "Start": "2026-09-30T12:04:54.906335376-07:00",
      "End": "2026-09-30T12:04:55.230771472-07:00",
      "ExitCode": 0,
      "Output": ""
    },
    {
      "Start": "2026-09-30T12:05:25.232382276-07:00",
      "End": "2026-09-30T12:05:25.440173854-07:00",
      "ExitCode": 0,
      "Output": ""
    },
    {
      "Start": "2026-09-30T12:05:55.441863452-07:00",
      "End": "2026-09-30T12:05:55.642373913-07:00",
      "ExitCode": 0,
      "Output": ""
    }
  ]
}

dogfood@dogfood:~/self-hosted$ docker inspect --format '{{json .State.Health}}' sentry-self-hosted-snuba-api-1 | jq .
{
  "Status": "healthy",
  "FailingStreak": 0,
  "Log": [
    {
      "Start": "2026-09-30T12:04:08.216791452-07:00",
      "End": "2026-09-30T12:04:17.133449981-07:00",
      "ExitCode": 1,
      "Output": "http://127.0.0.1:1218/health unreachable: [Errno 111] Connection refused\n"
    },
    {
      "Start": "2026-09-30T12:04:47.134760908-07:00",
      "End": "2026-09-30T12:04:49.831960055-07:00",
      "ExitCode": 0,
      "Output": ""
    },
    {
      "Start": "2026-09-30T12:05:19.833334594-07:00",
      "End": "2026-09-30T12:05:20.431751363-07:00",
      "ExitCode": 0,
      "Output": ""
    },
    {
      "Start": "2026-09-30T12:05:50.433122228-07:00",
      "End": "2026-09-30T12:05:50.981415871-07:00",
      "ExitCode": 0,
      "Output": ""
    },
    {
      "Start": "2026-09-30T12:06:20.982907985-07:00",
      "End": "2026-09-30T12:06:21.521793874-07:00",
      "ExitCode": 0,
      "Output": ""
    }
  ]
}

@aminvakil

Copy link
Copy Markdown
Collaborator

This decreases docker healthcheck set by HEALTHCHECK_TIMEOUT=1m30s in .env to 2 seconds.

Is that ok?

@aldy505

aldy505 commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

This decreases docker healthcheck set by HEALTHCHECK_TIMEOUT=1m30s in .env to 2 seconds.

Is that ok?

Right. I don't think this is okay and we have to provide compatibility for this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

4 participants