# Health Check ## Purpose Expose a public health endpoint for availability verification by load balancers, orchestrators, and container healthchecks (SPEC §5.1, §15.5). ## Requirements ### Requirement: Public health endpoint responds without authentication The system SHALL expose `GET /up` as a public healthcheck endpoint that does not require authentication. #### Scenario: Application is healthy - **WHEN** a client sends `GET /up` while the application is running normally - **THEN** the system responds with HTTP 200 in a timely manner #### Scenario: Health endpoint exposes no secrets - **WHEN** a client sends `GET /up` - **THEN** the response MUST NOT include credentials, tokens, stack traces, or environment secrets ### Requirement: Health endpoint reflects application failure The system SHALL return a failure status when the application cannot initialize properly. #### Scenario: Application cannot boot - **WHEN** the application fails to boot due to misconfiguration or missing dependencies - **THEN** the health endpoint MUST NOT return HTTP 200