How CogniPrep built a public health endpoint without leaking infrastructure secrets
CogniPrep's /api/health endpoint is intentionally public and unauthenticated, designed so uptime monitors remain functional even during incidents. The endpoint deliberately withholds sensitive details: database errors are logged internally via Sentry but callers receive only a status word, preventing disclosure of hostnames or role names. Missing environment variables are reported as a count rather than by name, so an anonymous caller cannot determine which specific service configuration is broken. Redis and monitoring integrations return only 'configured' or 'not_configured', never exposing URLs or credentials. The endpoint returns HTTP 503 only on genuine failures, while slowness triggers a 'degraded' status with HTTP 200, avoiding alert fatigue from transient cold-start latency.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in