Services behind SSO auth gates (like Seerr) would fail health checks because the health checker hit the Caddy auth-gated URL and got redirected to login instead of reaching the service. The healthCheckUrl field in services.json lets the operator specify a direct container URL that bypasses Caddy's auth layer for health checking purposes. Priority order in resolveServiceUrl(): 1. internet → fixed google.com 2. healthCheckUrl → direct container URL (NEW) 3. isExternal + externalUrl 4. service.url 5. dnsServers config 6. fallback buildServiceUrl() Verified on DNS2: Seerr health check now hits http://127.0.0.1:5055 directly instead of https://requests.sami through the SSO gate.