mirror of
https://github.com/pgsty/minio.git
synced 2026-08-10 00:03:29 +03:00
2ff594f4bb
Add 'silo healthcheck [live|ready|cluster|cluster-read]', a thin anonymous HTTP client for the server's own /minio/health/* endpoints, so containers without a shell, curl, or mc can still run health checks. Design: silo.pgsty.com/compatibility/feature/healthcheck/ The check vocabulary maps 1:1 onto the health API paths; the probe target is derived from the server's own --address/MINIO_ADDRESS contract with HTTPS auto-detected from the certs directory, and can be overridden with --url. Exit codes are 0/1 only (Docker reserves 2); diagnostics (x-minio-server-status, quorum headers) go into a single output line for docker inspect. The request is strictly anonymous (a credentialed request would be rejected by the reserved-path guard), the transport bypasses HTTP_PROXY, and certificate verification is skipped to match kubelet HTTPS probe behavior. Cluster checks default to a 15s deadline so the server's 10s cluster_deadline can elapse. Compatibility notes: the preserved /minio/health/* path literals and the MINIO_ADDRESS env var are upstream wire/config surface, reused on purpose; the rebrand-guard baseline is regenerated for the new route literals (tests included) with zero new exported symbols. The docker entrypoint argv translation learns the new command name. Verified: unit tests, entrypoint tests, go vet, plus an end-to-end run against a live server covering all four checks, --maintenance (412), --json, usage errors, unreachable and timeout paths. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
49 lines
1.3 KiB
Bash
Executable File
49 lines
1.3 KiB
Bash
Executable File
#!/bin/sh
|
|
#
|
|
|
|
# Run Silo by default, while translating the legacy argv-level command name.
|
|
# An explicitly supplied shell or utility remains an explicit entrypoint command.
|
|
case "${1:-}" in
|
|
"")
|
|
set -- silo
|
|
;;
|
|
minio)
|
|
shift
|
|
set -- silo "$@"
|
|
;;
|
|
silo)
|
|
;;
|
|
-*|server|fmt-gen|healthcheck)
|
|
set -- silo "$@"
|
|
;;
|
|
esac
|
|
|
|
ensure_writable_home() {
|
|
# The image is commonly run with an arbitrary UID or with the legacy
|
|
# MINIO_USERNAME drop-user path. Do not leave those processes pointing at
|
|
# root's inaccessible home: Silo probes its default configuration directory
|
|
# during process initialization.
|
|
if [ -z "${HOME:-}" ] || [ "${HOME}" = /root ] || [ ! -d "${HOME}" ] || [ ! -w "${HOME}" ]; then
|
|
HOME=/tmp
|
|
export HOME
|
|
fi
|
|
}
|
|
|
|
docker_switch_user() {
|
|
ensure_writable_home
|
|
if [ -n "${MINIO_USERNAME}" ] && [ -n "${MINIO_GROUPNAME}" ]; then
|
|
if [ -n "${MINIO_UID}" ] && [ -n "${MINIO_GID}" ]; then
|
|
exec chroot --userspec="${MINIO_UID}:${MINIO_GID}" / "$@"
|
|
else
|
|
echo "${MINIO_USERNAME}:x:1000:1000:${MINIO_USERNAME}:/:/sbin/nologin" >>/etc/passwd
|
|
echo "${MINIO_GROUPNAME}:x:1000" >>/etc/group
|
|
exec chroot --userspec="${MINIO_USERNAME}:${MINIO_GROUPNAME}" / "$@"
|
|
fi
|
|
else
|
|
exec "$@"
|
|
fi
|
|
}
|
|
|
|
## DEPRECATED and unsupported - switch to user if applicable.
|
|
docker_switch_user "$@"
|