From f268c4d9ba775b26e484349d39e06d9f445f4194 Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Thu, 13 Aug 2026 21:39:38 +1000 Subject: [PATCH] ghp: probe/scrape over HTTPS to match TLS metrics endpoint ghp serves metrics over HTTPS (TLS configured globally), but the liveness/readiness probes used the default HTTP scheme, so the kubelet probe hit an HTTPS-server error and pods never went Ready. Set scheme: HTTPS on both probes (kubelet does not verify the probe cert). The VMServiceScrape targets that same HTTPS endpoint, so set scheme: https with tlsConfig.insecureSkipVerify (internal-CA cert, pod-IP target not in the cert SANs); otherwise VM scraping of ghp fails. - deployment.yaml: liveness+readiness probes scheme HTTP -> HTTPS - vmservicescrape.yaml: scheme https + tlsConfig.insecureSkipVerify --- apps/base/ghp/deployment.yaml | 4 ++-- apps/base/ghp/vmservicescrape.yaml | 5 +++++ 2 files changed, 7 insertions(+), 2 deletions(-) diff --git a/apps/base/ghp/deployment.yaml b/apps/base/ghp/deployment.yaml index c6c9c25..1a7f5b2 100644 --- a/apps/base/ghp/deployment.yaml +++ b/apps/base/ghp/deployment.yaml @@ -102,7 +102,7 @@ spec: httpGet: path: /metrics port: metrics - scheme: HTTP + scheme: HTTPS initialDelaySeconds: 30 periodSeconds: 30 successThreshold: 1 @@ -112,7 +112,7 @@ spec: httpGet: path: /metrics port: metrics - scheme: HTTP + scheme: HTTPS initialDelaySeconds: 10 periodSeconds: 5 successThreshold: 1 diff --git a/apps/base/ghp/vmservicescrape.yaml b/apps/base/ghp/vmservicescrape.yaml index a91bde9..e5ca485 100644 --- a/apps/base/ghp/vmservicescrape.yaml +++ b/apps/base/ghp/vmservicescrape.yaml @@ -16,3 +16,8 @@ spec: endpoints: - port: metrics path: /metrics + scheme: https + # ghp serves metrics over TLS with an internal-CA cert; skip verification + # since the scrape targets a pod IP the cert SANs do not cover. + tlsConfig: + insecureSkipVerify: true