Skip to content

fix(infra): resolve flute-gateway and bgutil-pot-provider healthcheck failures - #915

Merged
POWERFULMOVES merged 1 commit into
mainfrom
fix/healthcheck-timeout-and-pgrep
Mar 14, 2026
Merged

POWERFULMOVES merged 1 commit into
mainfrom
fix/healthcheck-timeout-and-pgrep

Conversation

@POWERFULMOVES

@POWERFULMOVES POWERFULMOVES commented Mar 14, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • flute-gateway: Increase healthcheck timeout (5→10s in urllib request, 10→15s healthcheck timeout) and start_period (15→60s) to allow TTS provider initialization
  • bgutil-pot-provider: Replace pgrep with kill -0 1 (pgrep not available in the minimal container image)

Testing

Restarted both services and verified health status:

  • bgutil-pot-provider: Now healthy (kill -0 1 works where pgrep failed)
  • flute-gateway: Now healthy (60s start_period allows TTS provider initialization)
docker compose ps flute-gateway bgutil-pot-provider
# Both show (healthy)

Fixes #882

Summary by CodeRabbit

  • Bug Fixes
    • Fixed JWT authentication token decoding to correctly process all supported token formats, resolving user identification and access control issues in the ingest dashboard.
    • Enhanced service health check mechanisms with optimized timeout configurations and extended startup grace periods, improving service availability detection and system resilience.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@github-actions

Copy link
Copy Markdown
Contributor

Docker Hardening Validation

Hardening Validation Report

Validated: Sat Mar 14 01:49:18 UTC 2026

Services Checked

PMOVES.AI Docker Hardening Validation

[INFO] Checking: pmoves/docker-compose.hardened.yml

[INFO] Validating: hi-rag-gateway-v2
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: extract-worker
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: langextract
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: presign
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: render-webhook
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: retrieval-eval
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pdf-ingest
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: jellyfin-bridge
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: invidious-companion-proxy
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: ffmpeg-whisper
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-video
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-audio
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-v2-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: deepresearch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supaserch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: publisher-discord
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: mesh-agent
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-req
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-res
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: publisher
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: analysis-echo
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: graph-linker
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: comfy-watcher
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: grayjay-plugin-host
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: agent-zero
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: archon
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: channel-monitor
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pmoves-yt
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: notebook-sync
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supabase_service_role_key
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

[INFO] Validating: supabase_jwt_secret
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

======================================
Summary: 120 passed, 40 warnings, 0 errors

@coderabbitai

coderabbitai Bot commented Mar 14, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 21aa2d9a-f5d0-404b-8f60-c893c477cfec

📥 Commits

Reviewing files that changed from the base of the PR and between e55696a and 2b4196e.

📒 Files selected for processing (3)
  • pmoves/docker-compose.yml
  • pmoves/ui/app/dashboard/ingest/page.tsx
  • pmoves/ui/lib/supabaseClient.ts

📝 Walkthrough

Walkthrough

The changes update Docker healthchecks to use PID existence checks instead of process scanning, extend timeouts and grace periods, and fix JWT payload decoding to correctly handle URL-safe Base64 encoding in UI utilities.

Changes

Cohort / File(s) Summary
Docker Healthchecks
pmoves/docker-compose.yml
Replaced process grep healthchecks with PID existence checks (kill -0 1) for pmoves and bgutil-pot-provider services. Extended timeouts and start periods: bgutil-pot-provider timeout 10s→15s (start_period 15s→60s), flute-gateway timeout 5s→10s/15s (start_period 15s→60s).
JWT Base64url Decoding
pmoves/ui/app/dashboard/ingest/page.tsx, pmoves/ui/lib/supabaseClient.ts
Fixed JWT payload decoding to correctly handle URL-safe Base64 encoding by converting characters (- to +, \_ to /) before JSON parsing. Affects token payload extraction in both ingest dashboard and Supabase client utilities.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~12 minutes

Possibly related PRs

Poem

🐰 The wise rabbit hops through Base64 lands,
Converting dashes, underscores—oh, such demands!
While Docker springs forth with PID's keen eye,
And timeouts extend, letting services fly! ✨

🚥 Pre-merge checks | ✅ 2 | ❌ 3

❌ Failed checks (3 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning The PR's scope (healthcheck fixes) differs significantly from the linked issue #882 objectives (n8n postgres integration, workflow registry, bootstrap commands), creating a scope mismatch. Clarify whether this PR should be linked to issue #882 or if it should reference a different issue more directly related to healthcheck failures.
Out of Scope Changes check ⚠️ Warning Changes to JWT decoding in dashboard and supabase client files appear unrelated to the stated objectives of fixing container healthchecks. Explain the purpose of JWT decoding changes in page.tsx and supabaseClient.ts, or consider moving them to a separate PR focused on JWT base64url handling.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The PR title accurately reflects the main changes: fixing healthcheck failures in flute-gateway and bgutil-pot-provider services by adjusting timeouts and replacing pgrep with kill -0.
Description check ✅ Passed The PR description includes a clear summary of changes and testing verification, but omits the required 'CHIT Contract Check' and documentation sections from the template.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
  • 📝 Generate docstrings (stacked PR)
  • 📝 Generate docstrings (commit on current branch)
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch fix/healthcheck-timeout-and-pgrep
📝 Coding Plan
  • Generate coding plan for human review comments

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🧹 Nitpick comments (2)
pmoves/docs/AGENTS/CODEX_CLAUDE_PARITY_GAPS.md (1)

54-61: Documentation accurately reflects current parity gaps.

The missing tokens are correctly identified. Per the coding guidelines for this file, consider adding these tokens to close the gaps:

  • chit:review-sweep
  • chit:sign-trail
  • docs:reconcile
  • tac:review

The corresponding parity map (CODEX_CLAUDE_PARITY_MAP.md) should also be updated to maintain consistency.

Would you like me to help draft the parity map entries for these missing tokens, or open an issue to track this work?

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/docs/AGENTS/CODEX_CLAUDE_PARITY_GAPS.md` around lines 54 - 61, The
docs list in CODEX_CLAUDE_PARITY_GAPS.md omits four tokens that should be added
to close parity gaps; add the four tokens (`chit:review-sweep`,
`chit:sign-trail`, `docs:reconcile`, `tac:review`) into the "Missing Tokens by
Prefix" section and then update the corresponding parity map file
CODEX_CLAUDE_PARITY_MAP.md to include matching entries for those exact token
keys so documentation and the parity map remain consistent.
pmoves/configs/tac_trees/agent-zero-customization.tac.yaml (1)

241-249: Grep pattern may produce false positives.

The pattern agent-zero:|healthcheck: will match any service that has a healthcheck: block, not specifically the agent-zero service's healthcheck. This could lead to false pass results.

Consider a more specific pattern that ensures both terms appear in proximity:

♻️ Suggested pattern refinement
         - id: agent-zero.security.docker.healthcheck
           task: "Verify health check in compose"
           action:
             type: grep
             target: "pmoves/docker-compose.yml"
-            pattern: "agent-zero:|healthcheck:"
+            pattern: "agent-zero:(?:[\\s\\S]*?)healthcheck:"
             expect: "Docker compose includes healthcheck for agent-zero"
           context: "Required for orchestration and service discovery"
           agent_hint: codex

Alternatively, consider using two separate checks or a manual review action for this verification.

🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@pmoves/configs/tac_trees/agent-zero-customization.tac.yaml` around lines 241
- 249, The current check id agent-zero.security.docker.healthcheck uses the
pattern "agent-zero:|healthcheck:" which can match a healthcheck in any service;
update the check so it only passes when the agent-zero service has a healthcheck
by making the grep target more specific or ensuring proximity — e.g., match
"agent-zero:" followed within a few lines by "healthcheck:" or split into two
checks (one that finds "agent-zero:" and a second that confirms a subsequent
"healthcheck:" block) so false positives are eliminated; adjust the pattern or
replace the single grep action with two actions that reference id
agent-zero.security.docker.healthcheck (or new ids) accordingly.
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.

Inline comments:
In `@PMOVES-a0-plugins`:
- Line 1: Update the submodule pointer for PMOVES-a0-plugins to reference a real
commit on the PMOVES.AI-Edition-Hardened branch: replace the non-existent commit
8dfc1f63aee1881c5fc0b891c013ccb4b18b0f57 with the actual HEAD commit
00d6a87843f190c48b22e3b0c282c0a6a2a823a2 (or another valid commit from branch
PMOVES.AI-Edition-Hardened), commit the submodule update, and push the change so
submodule initialization succeeds.

In `@pmoves/ui/app/api/health/boot-jwt/route.ts`:
- Around line 9-11: The JWT payload decoding correctly converts base64url to
base64 in route.ts but the same conversion is missing in decodeJwtExp (function
decodeJwtExp) in pmoves/ui/lib/supabaseClient.ts and in the ownerIdFromToken
extraction in pmoves/ui/app/dashboard/ingest/page.tsx; update both to perform
.replace(/-/g, '+').replace(/_/g, '/') on the JWT parts[1] before calling
Buffer.from(..., 'base64') so the payload is decoded per RFC 7519 and parsed
reliably into JSON.

---

Nitpick comments:
In `@pmoves/configs/tac_trees/agent-zero-customization.tac.yaml`:
- Around line 241-249: The current check id
agent-zero.security.docker.healthcheck uses the pattern
"agent-zero:|healthcheck:" which can match a healthcheck in any service; update
the check so it only passes when the agent-zero service has a healthcheck by
making the grep target more specific or ensuring proximity — e.g., match
"agent-zero:" followed within a few lines by "healthcheck:" or split into two
checks (one that finds "agent-zero:" and a second that confirms a subsequent
"healthcheck:" block) so false positives are eliminated; adjust the pattern or
replace the single grep action with two actions that reference id
agent-zero.security.docker.healthcheck (or new ids) accordingly.

In `@pmoves/docs/AGENTS/CODEX_CLAUDE_PARITY_GAPS.md`:
- Around line 54-61: The docs list in CODEX_CLAUDE_PARITY_GAPS.md omits four
tokens that should be added to close parity gaps; add the four tokens
(`chit:review-sweep`, `chit:sign-trail`, `docs:reconcile`, `tac:review`) into
the "Missing Tokens by Prefix" section and then update the corresponding parity
map file CODEX_CLAUDE_PARITY_MAP.md to include matching entries for those exact
token keys so documentation and the parity map remain consistent.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 8dd60b24-6eda-496c-a607-0ba8269952ab

📥 Commits

Reviewing files that changed from the base of the PR and between 7f7e87c and e55696a.

📒 Files selected for processing (9)
  • .gitmodules
  • PMOVES-Agent-Zero
  • PMOVES-a0-plugins
  • pmoves/configs/tac_trees/agent-zero-customization.tac.yaml
  • pmoves/docker-compose.yml
  • pmoves/docs/AGENTS/CODEX_CLAUDE_PARITY_GAPS.md
  • pmoves/ui/app/api/health/boot-jwt/route.ts
  • pmoves/ui/playwright.config.ts
  • pmoves/ui/scripts/with-env.mjs

Comment thread PMOVES-a0-plugins Outdated
Comment thread pmoves/ui/app/api/health/boot-jwt/route.ts
- Increase flute-gateway healthcheck timeout to 15s, start_period to 60s
- Replace pgrep healthcheck with kill -0 1 for bgutil-pot-provider
- Fix JWT base64url decoding in boot-jwt route, supabaseClient, ingest page

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@POWERFULMOVES
POWERFULMOVES force-pushed the fix/healthcheck-timeout-and-pgrep branch from b7a2904 to 2b4196e Compare March 14, 2026 21:01
@github-actions

Copy link
Copy Markdown
Contributor

Docker Hardening Validation

Hardening Validation Report

Validated: Sat Mar 14 21:02:11 UTC 2026

Services Checked

PMOVES.AI Docker Hardening Validation

[INFO] Checking: pmoves/docker-compose.hardened.yml

[INFO] Validating: hi-rag-gateway-v2
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: extract-worker
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: langextract
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: presign
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: render-webhook
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: retrieval-eval
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pdf-ingest
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: jellyfin-bridge
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: invidious-companion-proxy
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: ffmpeg-whisper
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-video
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: media-audio
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-v2-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: hi-rag-gateway-gpu
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: deepresearch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supaserch
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: publisher-discord
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: mesh-agent
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-req
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: nats-echo-res
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: publisher
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: analysis-echo
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: graph-linker
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: comfy-watcher
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: grayjay-plugin-host
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: agent-zero
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: archon
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: channel-monitor
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: pmoves-yt
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: notebook-sync
[PASS] Non-root user: 65532:65532
[PASS] Read-only filesystem
[PASS] All capabilities dropped
[PASS] No-new-privileges enabled
[WARN] No resource limits

[INFO] Validating: supabase_service_role_key
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

[INFO] Validating: supabase_jwt_secret
[WARN] No user directive
[WARN] No read_only directive
[WARN] No cap_drop: ["ALL"]
[WARN] No no-new-privileges
[WARN] No resource limits

======================================
Summary: 120 passed, 40 warnings, 0 errors

@POWERFULMOVES
POWERFULMOVES merged commit 10791cf into main Mar 14, 2026
18 checks passed
@POWERFULMOVES
POWERFULMOVES deleted the fix/healthcheck-timeout-and-pgrep branch March 15, 2026 18:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant