[PR #5949] [self-hosted] Use cscli lapi status for CrowdSec readiness check in installer #24404

Open
opened 2026-08-05 06:08:38 -04:00 by saavagebueno · 0 comments
Owner

Original Pull Request: https://github.com/netbirdio/netbird/pull/5949

State: closed
Merged: Yes


Describe your changes

The installer's CrowdSec readiness loop gated bouncer registration on cscli capi status, which checks Central API (CAPI) connectivity. Bouncer registration is a purely local operation against LAPI, so a CAPI 403 (e.g. rate limit, misconfiguration) would cause the installer to skip CrowdSec setup unnecessarily. Switch the wait to cscli lapi status to match the container healthcheck.

Related: #5944

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Docs on main already reference cscli lapi status (netbirdio/docs#709).

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Bug Fixes
    • Corrected the CrowdSec service health check validation during startup initialization to verify the appropriate API status endpoint, ensuring accurate service readiness detection.
**Original Pull Request:** https://github.com/netbirdio/netbird/pull/5949 **State:** closed **Merged:** Yes --- ## Describe your changes The installer's CrowdSec readiness loop gated bouncer registration on `cscli capi status`, which checks Central API (CAPI) connectivity. Bouncer registration is a purely local operation against LAPI, so a CAPI 403 (e.g. rate limit, misconfiguration) would cause the installer to skip CrowdSec setup unnecessarily. Switch the wait to `cscli lapi status` to match the container healthcheck. ## Issue ticket number and link Related: #5944 ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [ ] Created tests that fail without the change (if possible) > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) Docs on main already reference `cscli lapi status` (netbirdio/docs#709). ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Corrected the CrowdSec service health check validation during startup initialization to verify the appropriate API status endpoint, ensuring accurate service readiness detection. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
saavagebueno added the pull-request label 2026-08-05 06:08:38 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#24404