Diagnostics
Check host health
Section titled “Check host health”deku doctordeku doctor runs a set of checks and prints one row per check:
Status: okCHECK STATE DETAIL------------------------------------------------------------------------daemon ok dekud v0.1.12database ok query succeededdocker ok daemon reachableangie_config_dir ok /etc/angie/conf.d/dekuobject_store warn not configured; backups unavailableinventory ok 3 apps, 1 servicesencryption_at_rest warn no key configured; values and backups are stored in the clearTwo families of rows are conditional. A tls_certificates row appears once any app has TLS
enabled. The angie_acme_module, acme, and acme_certificate rows appear once automatic
certificates are enabled: the first reports the Angie build options, the second
validates the settings and the provider token, and the third reports whether a certificate has been
issued — as a warn, since asking is asynchronous and not being issued yet is normal.
States are ok, warn, and fail. A warn means a feature is unavailable while the host is still serving; a fail means something is broken. deku doctor exits 1 when any check has failed, so you can use it as a health gate in a script or monitoring probe.
The checks cover the daemon version, the database, the Docker daemon, the Angie config directory, the object store, encryption at rest, TLS certificates, automatic certificates, and the app and service inventory.
Stop a log stream after it goes quiet
Section titled “Stop a log stream after it goes quiet”deku logs --follow streams until you interrupt it. Add --timeout to stop after a period with no output:
deku logs my-app --follow --timeout 30The timer resets on every line, so the command exits 30 seconds after the app stops logging. Use it to capture a deploy or a boot sequence without leaving a process waiting for output that never comes.
Certificate expiry
Section titled “Certificate expiry”Deku does not issue or renew certificates. deku letsencrypt enable requires the certificate and
key files to exist already, so renewal is an operator or external-automation concern. What Deku
does provide is visibility:
deku letsencrypt status <app>prints the expiry date and days remaining, and warns when the certificate is expiring (inside 14 days), expired, missing, or unreadable.--jsonreturns the raw payload, includinglifecycle,expires_at, anddays_remaining.deku doctorreports atls_certificatescheck across every TLS-enabled app and fails when any certificate is missing or expired.- The dashboard’s routing panel shows how long the certificate is valid for, with a warning callout.
- The alert watcher raises
certificate_expiring,certificate_expired, andcertificate_missingalerts, delivered over the hook surface like any other event.
Certificates live at /etc/angie/ssl/deku_<app>.crt and /etc/angie/ssl/deku_<app>.key.