fix: use tcp startup probes for tls-backed workloads#2307
Merged
AndrewChubatiuk merged 1 commit intoJun 19, 2026
Conversation
Contributor
|
@immanuwell @vrutkovs |
Contributor
Author
|
@AndrewChubatiuk I didn't switch TLS endpoints to default TCP livenessProbe/readinessProbe because, per the discussion in #1824 these probes only verify that the listener is accepting connections, not that the app is actually healthy or meaningfully ready so the agreed direction was to use a TCP startupProbe for the default TLS/mTLS case, and not keep steady-state default liveness/readiness checks with weaker semantics custom probes still override this, so users who want TCP liveness/readiness can set them explicitly that's my understanding of the agreed direction, maybe I'm wrong |
AndrewChubatiuk
approved these changes
Jun 19, 2026
Contributor
|
LGTM! Thanks for contribution! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1824
When a managed app enables TLS on its HTTP endpoint, the operator still renders default
httpGetapp probes. kubelet hits that endpoint without a TLS handshake, so health checks can fail even when the pod is fine.This keeps plain HTTP behavior as-is, and switches the default app probe to a
tcpSocketstartupProbeonly for TLS-backed endpoints when no custom probes are set. Custom probes still win, no funny business.Repro:
VMAuthwithspec.extraArgs.tls: "true"and no custom probes.httpGetprobes on the app port.Checks:
go test ./internal/controller/operator/factory/...make test