prole/supabase/helm/knoe-supabase/templates/studio/backendconfig.yaml
chrisfu 0f2fe93ebf fix(net): GCE BackendConfig rejects type: TCP; switch to HTTP /healthz
Follow-up to 391c4f5. Live deploy showed GCE's L7 BackendConfig CRD
hard-rejects type: TCP with:

  Error syncing to GCP: error running backend syncing routine:
  error ensuring health check:
  Protocol "TCP" is not valid, must be one of [HTTP,HTTPS,HTTP2]

The sync never completes, so the LB has no healthy backend and TCP
connections to the public endpoint just close (ERR_CONNECTION_CLOSED).

Fix: switch all three BackendConfigs to type: HTTP with request paths
that return 200:

- supabase-kong & knoe-svc-kong: add a dedicated /healthz route to the
  Kong declarative config via the request-termination plugin, which
  returns 200 synchronously with no upstream call. Equivalent liveness
  semantics to the TCP check we wanted (backend is alive as long as Kong
  accepts connections) but over HTTP, which GCE actually accepts.
  - supabase/helm/knoe-supabase/templates/kong/config.yaml
  - etc/init_kong.sh (inline kong.yml heredoc)

- supabase-studio: Studio returns 301 on / (Next.js default) so we
  point the probe at /favicon.ico -- Next.js serves it as a static asset
  with 200 unconditionally. Not as clean as a real readiness endpoint
  but Studio does not expose one that returns 200 without auth.
  - supabase/helm/knoe-supabase/templates/studio/backendconfig.yaml

Verified locally via helm template -f values.generated.json: the
rendered BackendConfigs come out with the HTTP protocol + correct paths,
and the Kong ConfigMap has the healthz service block before the
auth-v1-open service.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-21 12:05:40 -07:00

36 lines
1.3 KiB
YAML

{{- /*
GCE L7 BackendConfig for supabase-studio.
Mirror of kong/backendconfig.yaml. Studio is a Next.js app on port 3000
that returns 301 redirects on `/` (not 200), tripping GCE's default HTTP
healthCheck and marking the backend UNHEALTHY.
We wanted TCP liveness semantics but GCE's BackendConfig rejects `type:
TCP` (see kong/backendconfig.yaml for the exact error). Workaround: hit
`/favicon.ico` -- Next.js serves the favicon as a static asset and
returns 200 unconditionally, so the probe passes as long as the Next.js
server is up. Not as clean as a real readiness endpoint, but Studio does
not expose one that returns 200 without auth.
Rendered only when .Values.service.studio.backendConfigName is set.
*/ -}}
{{- if and .Values.deployment.studio.enabled (.Values.service.studio.backendConfigName | default "") -}}
apiVersion: cloud.google.com/v1
kind: BackendConfig
metadata:
name: {{ .Values.service.studio.backendConfigName | quote }}
labels:
{{- include "supabase.labels" . | nindent 4 }}
spec:
healthCheck:
type: HTTP
requestPath: /favicon.ico
port: {{ .Values.service.studio.port | default 3000 }}
checkIntervalSec: 15
timeoutSec: 5
healthyThreshold: 1
unhealthyThreshold: 3
connectionDraining:
drainingTimeoutSec: 30
{{- end }}