From 1861343f9fcab43f7e841ad3b35b97a64cce40bd Mon Sep 17 00:00:00 2001 From: duynguyen Date: Thu, 3 Sep 2026 15:57:47 +0700 Subject: [PATCH] fix: stop actual-budget-exporter probes from hitting login-triggering /metrics readinessProbe/livenessProbe hit /metrics on top of Prometheus's own scrapes; exporter re-logs into actual_server on every call (no session reuse), tripped actual_server's login rate limit (too-many-requests). Switch probes to tcpSocket and stretch scrape interval to 5m. --- .../chart/templates/deployment.yaml | 14 ++++++++------ apps/actual-budget-exporter/chart/values.yaml | 4 +++- 2 files changed, 11 insertions(+), 7 deletions(-) diff --git a/apps/actual-budget-exporter/chart/templates/deployment.yaml b/apps/actual-budget-exporter/chart/templates/deployment.yaml index 7a223dc..b88be53 100644 --- a/apps/actual-budget-exporter/chart/templates/deployment.yaml +++ b/apps/actual-budget-exporter/chart/templates/deployment.yaml @@ -41,17 +41,19 @@ spec: key: ACTUAL_E2E_PASSWORD_1 resources: {{- toYaml .Values.resources | nindent 12 }} - # No documented dedicated health endpoint; /metrics is the route - # that's always up once the exporter has started. + # /metrics does a full login against actual_server on every hit + # (see actual-api-service.js: initializeApi() runs per getMetrics() + # call) — an httpGet probe against it every 10-20s was stacking on + # top of Prometheus's own scrapes and tripped actual_server's + # login-attempt rate limit ("too-many-requests"). Probe TCP only; + # let Prometheus be the sole thing that ever calls /metrics. readinessProbe: - httpGet: - path: /metrics + tcpSocket: port: {{ .Values.service.port }} initialDelaySeconds: 5 periodSeconds: 10 livenessProbe: - httpGet: - path: /metrics + tcpSocket: port: {{ .Values.service.port }} initialDelaySeconds: 15 periodSeconds: 20 diff --git a/apps/actual-budget-exporter/chart/values.yaml b/apps/actual-budget-exporter/chart/values.yaml index c255d88..b8a4093 100644 --- a/apps/actual-budget-exporter/chart/values.yaml +++ b/apps/actual-budget-exporter/chart/values.yaml @@ -34,4 +34,6 @@ resources: serviceMonitor: enabled: true - interval: 30s + # Each scrape does a full login against actual_server (no session reuse in + # this exporter) — kept long to avoid tripping its login rate limit. + interval: 5m