Repository navigation
Add liveness/readiness probes, a locked-down CORS allowlist, and graceful shutdown - #1910
Merged
yusuftomilola merged 2 commits intoSep 25, 2026
Conversation
…aceful shutdown Adds a Terminus-based HealthModule: GET /health is a dependency-free liveness probe and GET /health/ready is a readiness probe that pings TypeORM with a bounded timeout and reports 503 when the database is unreachable. The pre-existing combined dependency view moves to GET /health/dependencies so it no longer shadows the liveness route. Locks CORS down to an explicit per-environment allowlist driven by CORS_ORIGINS. Development and test fall back to the two local frontend origins; production falls closed to an empty allowlist and logs a warning, so a misconfigured deploy denies cross-origin traffic instead of allowing it. Credentialed requests are still supported. Adds bounded, idempotent SIGTERM/SIGINT handling that closes the HTTP server, drains idle connections, runs Nest lifecycle hooks, and force-exits only after a configurable watchdog expires. Audits backend/.env.example against every variable the source actually reads, documents where each is read, and marks the reserved/unused entries explicitly. Closes DistinctCodes#1793 Closes DistinctCodes#1792 Closes DistinctCodes#1791 Closes DistinctCodes#1790
|
@limxiy is attempting to deploy a commit to the naijabuz's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@limxiy Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
…eck-env-graceful-shutdown # Conflicts: # backend/.env.example # backend/src/main.ts
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Closes four issues assigned to this account, all in the backend.
Orchestrator health probes (#1792)
Adds a
HealthModulebuilt on@nestjs/terminus:GET /health— liveness. Dependency-free; it must not inspect the database, because a database blip must not cause an orchestrator to kill an otherwise healthy pod.GET /health/ready— readiness. A realTypeOrmHealthIndicator.pingCheckwith a bounded, configurable timeout; Terminus turns an unreachable database into a 503 automatically.JwtAuthGuardis intentionally absent so probes and health checkers work; the globalThrottlerGuardstill applies. The pre-existing combined dependency view moved toGET /health/dependenciesso it no longer shadows the new liveness route — this is a route change: anything that previously usedGET /healthas a dependency check should use/health/readyor/health/dependencies.CORS allowlist (#1793)
The app never called
enableCors, so the implicit allow-all applied to a credentialed API. CORS is now an explicit per-environment allowlist driven byCORS_ORIGINS:Originheader (same-origin/non-browser clients, curl, probes) are allowed.backend/.env.example audit (#1791)
Enumerated every variable the backend actually reads (
process.env.*and everyConfigService.get*string key across auth, database, payments and adapters, Soroban/Stellar, wallets, credits, retention, common, andmain.ts) and diffed it against the file. The result is an annotated source-of-truth: each section states which file reads it, variables present in the file but read nowhere are marked[RESERVED/UNUSED]rather than silently deleted, and nothing the code reads is left undocumented.Graceful shutdown (#1790)
SIGTERM/SIGINTnow drain instead of dropping in-flight requests: stop accepting connections (server.close()+closeIdleConnections()), awaitapp.close()so Nest lifecycle hooks run, and force-exit only if a configurable watchdog expires. Re-entrant signals are ignored rather than running the hooks twice. The logic lives in an exported, injectable helper so it is unit-testable without spawning a process.Configuration
CORS_ORIGINSHEALTH_CHECK_TIMEOUT_MS3000(capped at 30000)GRACEFUL_SHUTDOWN_TIMEOUT_MS30000Testing
Per the task constraints, no install, build, lint, or test run was performed — the maintainer runs those manually.
New specs:
common/cors.spec.ts,common/graceful-shutdown.spec.ts,health/health.controller.spec.ts.backend/package-lock.jsonis intentionally not regenerated;@nestjs/terminusis declared inpackage.jsonand the lockfile needs annpm installbeforenpm ciwill succeed.New dependency
@nestjs/terminus(NestJS 10-compatible line).Closing issues
Closes #1793
Closes #1792
Closes #1791
Closes #1790