Stop the caddy-502-rate alert firing on every deploy
The journal/planner deploy in cd-apps.yml does `docker compose up -d journal planner`, which stops the old container and starts the new one — Caddy keeps forwarding requests during the ~10–30s gap and returns 502s. The caddy-502-rate alert (threshold > 0 for 2m) correctly trips, every time. Two production changes plus a long-broken workflow detail: - infrastructure/Caddyfile — add `lb_try_duration 30s` / `lb_try_interval 250ms` to the journal and planner reverse_proxy blocks. Caddy now holds and retries the upstream for up to 30s during a restart instead of 502'ing immediately. Real outages (upstream unreachable longer than 30s) still 502 and the alert still fires for those. - infrastructure/grafana/provisioning/alerting/alerts.yml — add a comment documenting why caddy-502-rate stays at threshold > 0: with lb_try_duration in front of it, the alert no longer conflates "deploy in flight" with "real outage." - .github/workflows/cd-apps.yml — fix a long-silent bug: the Grafana deploy-annotation step was reading GRAFANA_SERVICE_TOKEN from `.env`, but the secrets file we scp to /opt/trails-cool is named `app.env`. The token check failed silently and the curl was being skipped on every deploy. Switching to `app.env` so deploys actually annotate Grafana. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
153f133093
commit
5c4b6fd9af
3 changed files with 30 additions and 4 deletions
10
.github/workflows/cd-apps.yml
vendored
10
.github/workflows/cd-apps.yml
vendored
|
|
@ -115,8 +115,14 @@ jobs:
|
|||
docker image prune -af
|
||||
docker compose ps
|
||||
|
||||
# Annotate deploy in Grafana
|
||||
GRAFANA_TOKEN=$(grep GRAFANA_SERVICE_TOKEN .env | cut -d= -f2- 2>/dev/null)
|
||||
# Annotate deploy in Grafana. The token lives in the
|
||||
# decrypted SOPS env file we just scp'd to /opt/trails-cool
|
||||
# — that file is `app.env`, not `.env`. (Pre-fix this read
|
||||
# the wrong path, so annotations were silently no-op'ing
|
||||
# every deploy.) `2>/dev/null` keeps a missing token from
|
||||
# failing the deploy; `|| true` keeps the curl from
|
||||
# failing the deploy if Grafana itself is unhealthy.
|
||||
GRAFANA_TOKEN=$(grep GRAFANA_SERVICE_TOKEN app.env 2>/dev/null | cut -d= -f2-)
|
||||
if [ -n "$GRAFANA_TOKEN" ]; then
|
||||
docker compose exec -T grafana curl -sf -X POST \
|
||||
-H "Authorization: Bearer $GRAFANA_TOKEN" \
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue