Skip to content

Report build version on /healthz via X-Epmon-Version - #69

Merged
Yanujz merged 1 commit into
mainfrom
issue-65-version-header
Sep 20, 2026
Merged

Yanujz merged 1 commit into
mainfrom
issue-65-version-header

Conversation

@Yanujz

@Yanujz Yanujz commented Sep 20, 2026

Copy link
Copy Markdown
Collaborator

What changes for operators?

/healthz carries X-Epmon-Version (release version from ldflags, dev locally), making the SECURITY.md reporting flow true as written and giving load balancers/curl build identity without exec. Additive API only (new setter, header omitted when unset).

Failing-then-passing test

New TestHealthzVersionHeader (present/absent halves): requires the new setter (build-fails on old code); passes with the fix. Package green with -race.

Checklist

  • go build ./... && go vet ./... && go test ./... green with -race (touched packages; full suite at merge)
  • gofmt -l . clean
  • OpenAPI updated if API surface changed — N/A (header only, no schema change)
  • No fabricated history — N/A
  • No secrets, tokens, or hosts I don't own in the diff

Fixes #65

SECURITY.md tells reporters to read the version from /healthz headers,
but no such header existed. Additive SetVersion on the API server, wired
to the release vars in main; unset means omitted.

Fixes #65
@Yanujz
Yanujz merged commit fc44231 into main Sep 20, 2026
1 check passed
@Yanujz
Yanujz deleted the issue-65-version-header branch September 20, 2026 10:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SECURITY.md promises a version header /healthz does not send

1 participant