Skip to content

fix(tls): add https fallback to health/readiness probes for TLS-only listeners - #209

Merged
yansigit merged 1 commit into
devfrom
codex/fix-tls-health-probe
Sep 2, 2026
Merged

yansigit merged 1 commit into
devfrom
codex/fix-tls-health-probe

Conversation

@yansigit

@yansigit yansigit commented Sep 2, 2026

Copy link
Copy Markdown
Owner

Summary

Fixes misleading Service repaired, but no proxy answered on port 10100 within 30s when hostname=0.0.0.0 + tls is configured. With TLS the main listener is HTTPS-only (Bun.serve({tls}) / canonicalServerOrigin -> https://…), but proxyIdentityAt and probeReadiness in src/server/proxy-liveness.ts probed http://127.0.0.1:10100/healthz via directLocalHttpFetch (HTTP-only node:net, rejects https: at direct-local-http.ts:238). The HTTP probe times out, confirmServiceServing in src/service.ts:688 returns ok:false, and the user sees the 30s warning even though the proxy is serving on HTTPS.

Minimal ponytail fix: on transport failure, one https:// retry via native fetch(…, {tls:{rejectUnauthorized:false}}) for self-signed loopback cert. Keeps directLocalHttpFetch HTTP-only (proxy bypass) and respects core-lab boundary / synchronous startServer window (no new imports from src/lab/).

Closes the root cause behind the repeated Reconnecting... waiting for network / OCX service repair requiring OPENCODEX_API_AUTH_TOKEN dance reported in remote session (local).

Verification

  • bun run typecheck — pass
  • bun test tests/proxy-liveness.test.ts tests/service.test.ts — 258 pass, 0 fail
  • bun test tests/core-lab-boundary.test.ts — 17 pass (no lab import leak, no await before activation window)
  • Manual: ocx service repair with OPENCODEX_API_AUTH_TOKEN=$(cat ~/.opencodex/service-api-token) no longer reports 30s timeout when TLS is enabled; curl -k https://127.0.0.1:10100/healthz returns opencodex healthz, http://127.0.0.1:10200 loopback still serves Codex openai_base_url

Checklist

  • Scope stays focused and avoids unrelated cleanup.
  • Docs or release notes were updated when needed. (no user-facing config change)
  • Security-sensitive changes were reviewed for secrets, auth, and unsafe defaults. (tls rejectUnauthorized only on loopback self-signed probe)

@github-actions github-actions Bot added the intake: hygiene-blocked Deterministic PR hygiene checks failed label Sep 2, 2026
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown

⚠️ Deterministic hygiene checks failed.

  • missing_regression_test — Behavior changed under src/ or gui/src/ without a test change. Add focused coverage or obtain test-exception-approved.

@github-actions github-actions Bot added the bug Something isn't working label Sep 2, 2026
@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

PR automation (bot-owned)

  • Class: draft (draft)
  • Base: 07fed8ded31c182e4e2f4b63ede1c93bd7900857
  • Head: 9002fb9be7b40bba6024dd708b7adb43da9ef851
  • Action: observed
  • Exact-head gate: BLOCKED (not-mergeable, check-missing, check-not-success)
  • Sensitive paths: none
  • Maintainer auto-merge approval: NO
  • Bot merge evidence: NO
  • Next action: human review required

@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

✅ READY

  • all PR quality gates passed.

Hygiene

✅ Deterministic PR hygiene checks passed.

@github-actions
github-actions Bot marked this pull request as draft September 2, 2026 02:26
…listeners

When hostname is 0.0.0.0 and tls is configured, port 10100 serves HTTPS-only.
proxyIdentityAt used directLocalHttpFetch (http-only TCP) -> timeout against TLS
port, causing confirmServiceServing to falsely warn 'no proxy answered'.
Added one https:// retry via native fetch with rejectUnauthorized:false per
attempt for both proxyIdentityAt (/healthz) and probeReadiness (/readyz).
Keeps directLocalHttpFetch bypassing proxy env; https via global fetch.

Fixes remote session reconnect loops where repair reported serving:false
@yansigit
yansigit force-pushed the codex/fix-tls-health-probe branch from d165cb0 to 9002fb9 Compare September 2, 2026 02:29
@github-actions github-actions Bot removed the intake: hygiene-blocked Deterministic PR hygiene checks failed label Sep 2, 2026
@github-actions
github-actions Bot marked this pull request as ready for review September 2, 2026 02:30
@yansigit
yansigit merged commit 6f66921 into dev Sep 2, 2026
28 checks passed
@yansigit
yansigit deleted the codex/fix-tls-health-probe branch September 2, 2026 02:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant