Add keepalive-status, a log-only session health check

Summarises the running container's keepalive: extension count, latest
budget, transient failures, rejections, restarts.

It deliberately makes no API call. Any authenticated request slides the
session TTL, so a checker that talked to Schulcloud would be sustaining
the session itself and could not report on whether the keepalive is
doing it — the same confound that made the first endurance test
ambiguous. Reading container logs observes without participating.

Warns when the reported budget drops below 7000s, which is the early
signal that extensions have stopped taking effect.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-12 16:39:50 +02:00
parent 9ce869f3fb
commit bf2e542182
5 changed files with 70 additions and 4 deletions

View File

@@ -157,7 +157,8 @@ npm run probe # re-verify the API assumptions
`MAX_DOWNLOAD_BYTES` (25 MiB default).
- **The Schulcloud session has a 2-hour sliding TTL**, so the server calls
`refresh-session` every 30 minutes. Watch for
`keepalive: session extended, 7200s` in the logs.
`keepalive: session extended, 7200s` in the logs, or run
`npm run keepalive-status` for a summary.
- **Never leave a Schulportal tab open on the token you deployed.** It shares
the session and its auto-logout will revoke it ~2h after login. Copy the
cookie in a private window and close it — see docs/AUTH.md.