Skip to content

Add container HEALTHCHECK and bump vulnerable Go dependencies - #1746

Closed
betterix wants to merge 3 commits into
cloudflare:masterfrom
betterix:docker-healthcheck-and-dep-bumps
Closed

betterix wants to merge 3 commits into
cloudflare:masterfrom
betterix:docker-healthcheck-and-dep-bumps

Conversation

@betterix

Copy link
Copy Markdown

Summary

  • Add a HEALTHCHECK to the Docker images so docker ps / Compose / Swarm can report whether the tunnel is actually up.
  • Bump Go dependencies flagged by Trivy that have upstream fixes.

Changes

Healthcheck

  • Set TUNNEL_METRICS=0.0.0.0:2000 so the metrics server listens on a known port.
  • Added:
    HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 CMD ["cloudflared", "tunnel", "--metrics", "127.0.0.1:2000", "ready"]
  • Uses the built-in ready command, so no shell or curl is needed in the distroless image.

Dependencies

Testing

  • Built the image and ran a quick tunnel: docker run -d cloudflared:test tunnel --url http://localhost:8080
  • docker inspect --format '{{.State.Health.Status}}' reports starting, then healthy once connected.
  • Re-ran trivy image: the fixed Go module findings are gone. The remaining libc6/zlib1g findings have no fixed version in the Debian base image.

@betterix betterix closed this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant