1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
//! `GET /health/live` and `GET /health/ready` (SPEC §11).
use Arc;
use State;
use StatusCode;
use crateApp;
/// Process liveness. True as soon as the router answers, and it stays true through
/// an expired blocklist or an unusable store — that is what readiness is for.
pub async
/// Valid policy, usable storage, service ready; no live upstream probe.
///
/// Readiness is exactly "is a valid blocklist in force?". Expiry needs no poller: the
/// window is compared against the clock on every request, which is the same reading
/// `policy::evaluate` decides with. SPEC §8: at expiry readiness becomes unhealthy
/// while liveness stays healthy.
///
/// Storage is checked explicitly from slice 7 on. Until then it held transitively —
/// a store that would not open published no snapshot, so readiness was already false.
/// Slice 7 adds a second writer, and SPEC §10 requires that a write failing *after* a
/// snapshot is in force turns readiness false too: "Storage write failures make
/// readiness false and deny package responses with `503` until storage is usable
/// again." `StoreHandle::is_healthy` is that flag, and it goes back to true when a
/// command succeeds again.
pub async
/// `503` while a decision-log record was lost in the last 60 s, `200` otherwise
/// (including with no sink). An alerting signal, not a probe target: `/health/ready`
/// stays green while records are shed, and no serving decision reads this state.
pub async