Skip to content

Reopen gateway replica SSH tunnels whose ssh process exited - #4353

Closed
alvils-ailab-stratcom wants to merge 1 commit into
dstackai:masterfrom
technicalbranch:fix/gateway-reopen-replica-tunnels
Closed

alvils-ailab-stratcom wants to merge 1 commit into
dstackai:masterfrom
technicalbranch:fix/gateway-reopen-replica-tunnels

Conversation

@alvils-ailab-stratcom

@alvils-ailab-stratcom alvils-ailab-stratcom commented Oct 8, 2026 •

Copy link
Copy Markdown

Reopen dead gateway replica tunnels.

Fixes #4352

The gateway opens one SSH tunnel per service replica when the replica is
registered and reuses it for every request, but never checks it again. If
the tunnel's ssh process exits (the replica's sshd drops a gateway that missed
keepalives under load, a network blip, or the process is killed), nginx keeps
forwarding to the abandoned Unix socket and the service returns 502 until the
gateway is restarted, while probes, which use their own tunnels, stay green.

Check every replica tunnel periodically (DSTACK_PROXY_TUNNEL_CHECK_INTERVAL,
default 15 s) through its control socket and reopen the ones whose ssh process
has exited. The local app socket path is kept, so nginx and the HTTP client
need no reconfiguration. A stale control socket left by a killed ssh process is
removed first, otherwise the new ssh would run without one and fail every
check. A per-connection lock keeps a reopen from resurrecting a connection that
is being closed.

Fixes dstackai#4352
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: Gateway keeps returning 502 after a replica SSH tunnel exits

1 participant