Answer image requests with 503 in maintenance mode (closes #71)
check / check (push) Successful in 3m29s

maintenance_mode was only reported by the health check; every request
was still served. One middleware in routes.go, applied to /v1/image/
and /v1/e/ only, now answers them with 503, a Retry-After of
MaintenanceRetryAfterSeconds and the JSON error body while it is on.
It calls Server.MaintenanceMode(), which had no caller.

The health check stays 200 and reports maintenance_mode, since the
image's Docker HEALTHCHECK and upaas read it; the login and URL
generator pages and /metrics keep working. Documented in README.md and
config.example.yml.

Model: opus-5-5
This commit is contained in:
2026-09-29 04:19:25 +00:00
parent 65cbf3f4f5
commit f70723ac4d
4 changed files with 67 additions and 9 deletions
+7
View File
@@ -30,6 +30,13 @@ exhaustion
# Completed Steps
- 2026-09-29 maintenance mode refuses image requests (closes #71): while
`maintenance_mode` is on, `/v1/image/` and `/v1/e/` answer 503 with a
`Retry-After` header and the JSON error body, from one middleware in
`internal/server/routes.go`; the health check stays 200 and reports
`maintenance_mode`, as the image's Docker `HEALTHCHECK` and upaas read it; the
login and URL generator pages and `/metrics` keep working; documented in
`README.md` and `config.example.yml`.
- 2026-09-29 `trusted_proxies` advice and signature padding in `README.md`
(closes #150): the login-limit paragraph, the `trusted_proxies` entry and
`config.example.yml` say to set `trusted_proxies` to the address pixa sees for