"""§17 health-check endpoint source. A small unauthenticated probe used by ops tooling (e.g. the flotilla deploy control panel) to verify a deploy landed correctly. The structural value is the version-match check — after `systemctl restart` reports active, the operator polls `/api/health` and verifies the returned `version` equals the tag just deployed, catching the failure mode where a restart did not pick up the new code. The version is read from the `VERSION` file at the repo root at import time (§20.1's canonical source) and cached as a module-level constant. A missing `VERSION` fails loudly per §20.6 rather than serving a placeholder — a silent default would defeat the version-match check that is the entire point of the endpoint. `status` is always `"ok"` (HTTP 200) in v1. The `"degraded"` / 503 path stays in the response shape so a later release can wire real degradation conditions (reconciler stuck, migrations pending, provider universe empty) without breaking the contract. """ from __future__ import annotations from pathlib import Path _VERSION_PATH = Path(__file__).resolve().parents[2] / "VERSION" def _read_version() -> str: text = _VERSION_PATH.read_text(encoding="utf-8").strip() if not text: raise RuntimeError(f"VERSION file at {_VERSION_PATH} is empty") return text VERSION: str = _read_version()