feat(helm): support configurable httpGet scheme on health probes

Add an optional `scheme` field (HTTP/HTTPS) to livenessProbe,
readinessProbe and startupProbe, wired into each probe's
httpGet.scheme and defaulting to HTTP.

When the proxy terminates TLS on the container port
(--ssl_keyfile_path / --ssl_certfile_path), the kubelet's
plain-HTTP probes fail the TLS handshake (EOF) and the pod never
becomes Ready. There was previously no way to make the probes use
HTTPS. Default stays HTTP so rendered output is unchanged for
existing users.

Adds helm-unittest cases asserting the HTTP default and the
HTTPS override on all three probes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Waldemar Majkowski 2026-06-03 18:29:40 +02:00
parent d45e9e4d56
commit dc10bf84b8
4 changed files with 43 additions and 1 deletions

View file

@ -18,7 +18,7 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 1.1.0
version: 1.2.0
# This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to

View file

@ -183,6 +183,7 @@ spec:
httpGet:
path: {{ .Values.livenessProbe.path | quote }}
port: "http"
scheme: {{ .Values.livenessProbe.scheme | default "HTTP" }}
initialDelaySeconds: {{ .Values.livenessProbe.initialDelaySeconds }}
periodSeconds: {{ .Values.livenessProbe.periodSeconds }}
timeoutSeconds: {{ .Values.livenessProbe.timeoutSeconds }}
@ -192,6 +193,7 @@ spec:
httpGet:
path: {{ .Values.readinessProbe.path | quote }}
port: "http"
scheme: {{ .Values.readinessProbe.scheme | default "HTTP" }}
initialDelaySeconds: {{ .Values.readinessProbe.initialDelaySeconds }}
periodSeconds: {{ .Values.readinessProbe.periodSeconds }}
timeoutSeconds: {{ .Values.readinessProbe.timeoutSeconds }}
@ -201,6 +203,7 @@ spec:
httpGet:
path: {{ .Values.startupProbe.path | quote }}
port: "http"
scheme: {{ .Values.startupProbe.scheme | default "HTTP" }}
initialDelaySeconds: {{ .Values.startupProbe.initialDelaySeconds }}
periodSeconds: {{ .Values.startupProbe.periodSeconds }}
timeoutSeconds: {{ .Values.startupProbe.timeoutSeconds }}

View file

@ -402,3 +402,34 @@ tests:
- equal:
path: spec.template.metadata.annotations["example.com/literal"]
value: "plain-string-value"
- it: should default probe httpGet scheme to HTTP
template: deployment.yaml
set:
image.tag: test
asserts:
- equal:
path: spec.template.spec.containers[0].livenessProbe.httpGet.scheme
value: HTTP
- equal:
path: spec.template.spec.containers[0].readinessProbe.httpGet.scheme
value: HTTP
- equal:
path: spec.template.spec.containers[0].startupProbe.httpGet.scheme
value: HTTP
- it: should set probe httpGet scheme to HTTPS when configured
template: deployment.yaml
set:
image.tag: test
livenessProbe.scheme: HTTPS
readinessProbe.scheme: HTTPS
startupProbe.scheme: HTTPS
asserts:
- equal:
path: spec.template.spec.containers[0].livenessProbe.httpGet.scheme
value: HTTPS
- equal:
path: spec.template.spec.containers[0].readinessProbe.httpGet.scheme
value: HTTPS
- equal:
path: spec.template.spec.containers[0].startupProbe.httpGet.scheme
value: HTTPS

View file

@ -91,6 +91,10 @@ service:
# Probes for LiteLLM gateway container
livenessProbe:
path: /health/liveliness
# Scheme for the probe request: HTTP (default) or HTTPS. Set to HTTPS when the
# proxy terminates TLS on the container port (ssl_keyfile_path/ssl_certfile_path),
# otherwise the kubelet's plain-HTTP probe fails the TLS handshake.
scheme: HTTP
initialDelaySeconds: 0
periodSeconds: 15
timeoutSeconds: 5
@ -99,6 +103,8 @@ livenessProbe:
readinessProbe:
path: /health/readiness
# See livenessProbe.scheme. HTTP (default) or HTTPS.
scheme: HTTP
initialDelaySeconds: 0
periodSeconds: 10
timeoutSeconds: 5
@ -107,6 +113,8 @@ readinessProbe:
startupProbe:
path: /health/readiness
# See livenessProbe.scheme. HTTP (default) or HTTPS.
scheme: HTTP
initialDelaySeconds: 0
periodSeconds: 10
timeoutSeconds: 5