## ADDED Requirements ### Requirement: Staging health and smoke use the public /up endpoint Staging healthchecks and post-deploy smoke MUST call `GET /up` without authentication and MUST treat a non-200 response as deployment failure (SPEC §15.5, §16.2). The health response MUST NOT expose secrets. #### Scenario: Staging healthcheck probes /up - **WHEN** Dokploy or the container runtime evaluates application health after deploy - **THEN** it MUST request `/up` - **AND** MUST require HTTP 200 before marking the service healthy #### Scenario: Smoke failure on /up fails the deploy gate - **WHEN** post-deploy smoke requests `/up` and receives a non-200 response - **THEN** the staging promotion MUST be considered failed