UDP Health Checker (proto)
This extension has the qualified name envoy.health_checkers.udp
Note
This extension is functional but has not had substantial production burn time, use only with this caveat.
This extension is intended to be robust against untrusted downstream traffic. It assumes that the upstream is trusted.
Tip
This extension extends and can be used with the following extension category:
This extension must be configured with one of the following type URLs:
extensions.health_checkers.udp.v3.UdpHealthCheck
[extensions.health_checkers.udp.v3.UdpHealthCheck proto]
Configuration for the UDP health checker.
For every health-check attempt, Envoy creates a fresh connected UDP socket targeting the host’s
health check address. UDP connect()
only selects the peer; it does not establish connectivity and does not count as a successful
health check. The reuse_connection setting does not apply.
Attempts for a host are serialized so that only one attempt is active at a time. Envoy sends
exactly one datagram containing send and waits for a response until the enclosing
HealthCheck.timeout expires.
The connected socket accepts datagrams only from the configured peer. Each complete response
datagram is compared byte-for-byte with receive. A matching datagram completes the attempt
successfully. Non-matching datagrams do not satisfy the check; Envoy continues waiting until a
matching datagram arrives or the attempt times out. A timeout or local socket error completes
the attempt unsuccessfully.
The enclosing HealthCheck controls thresholds, intervals, jitter, statistics, and event logging.
{
"send": {...},
"receive": {...}
}
- send
(config.core.v3.HealthCheck.Payload, REQUIRED) Payload sent as exactly one UDP datagram at the start of each health-check attempt. The decoded payload must not exceed 65,507 bytes. A smaller payload may be required to avoid IP fragmentation along the network path.
- receive
(config.core.v3.HealthCheck.Payload, REQUIRED) Expected response payload. A response datagram must match the entire payload exactly to make the health-check attempt successful. The decoded payload must not exceed 65,507 bytes. A smaller payload may be required to avoid IP fragmentation along the network path.