Tooling assumptions
- Use a terminal runner with bash and git available.
- Prefer
maketargets when available; fall back to direct CLI commands when needed.
Endpoints
GET /health(public): readiness/liveness check.GET /metrics(Prometheus): may be optionally protected.
Validate locally
curl -i http://localhost:8080/health
curl -i http://localhost:8080/metrics
If metrics auth is enabled:
# Use any token from AUTH_TOKENS
curl -i -H "Authorization: Bearer $YOUR_TOKEN" http://localhost:8080/metrics
Security note
Treat /metrics as potentially sensitive (rates, error counts, operational info). Enable protection in production with METRICS_AUTH_ENABLED=true or restrict via reverse proxy.