ci / Compose (pull_request) Successful in 27s
ci / Workflows (pull_request) Successful in 14s
ci / Shell (pull_request) Successful in 34s
ci / Python and tests (pull_request) Successful in 19s
ci / YAML (pull_request) Successful in 17s
ci / Dockerfiles (pull_request) Successful in 6s
ci / Formatting (pull_request) Successful in 36s
ci / Kubernetes (pull_request) Successful in 14s
ci / image-plan (pull_request) Skipped
ci / Image (${{ matrix.name }}) (pull_request) Skipped
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request_target) Successful in 3m13s
57 lines
2.4 KiB
Markdown
57 lines
2.4 KiB
Markdown
# Reloader
|
|
|
|
Restarts opted-in workloads when the ConfigMaps or Secrets they consume change.
|
|
The deploy workflow upgrades the `reloader` Helm release in namespace `reloader`;
|
|
`k8s/active` enables it. The chart version is pinned in `deploy-lib.sh`.
|
|
|
|
## Workload integration
|
|
|
|
Put this annotation on the Deployment or StatefulSet metadata:
|
|
|
|
```yaml
|
|
metadata:
|
|
annotations:
|
|
reloader.stakater.com/auto: "true"
|
|
```
|
|
|
|
The annotation belongs to the workload, not `spec.template.metadata`.
|
|
Reloader discovers references in environment variables and mounted volumes.
|
|
This covers startup-only settings and ConfigMaps or Secrets mounted with `subPath`.
|
|
See the [upstream usage guide](https://github.com/stakater/Reloader/blob/v1.4.22/README.md#usage).
|
|
|
|
The application manifests opt in workloads including AdGuard's TLS files,
|
|
NetBird, both NetBox processes, and the password-protected Valkey servers.
|
|
Inactive services have the same annotations ready for later activation.
|
|
|
|
## Controller policy
|
|
|
|
The controller watches all namespaces but only restarts annotated workloads.
|
|
It uses the `annotations` reload strategy, so changes trigger a pod-template
|
|
annotation rather than injecting extra environment variables.
|
|
|
|
Jobs and CronJobs are excluded: their next execution reads current configuration.
|
|
PostgreSQL is intentionally not opted in. Its password variables and init scripts
|
|
apply to first initialization; restarting an existing database does not rotate
|
|
roles or rerun those scripts. Rotate database credentials with SQL and update the
|
|
clients' Secrets together.
|
|
|
|
Helm-managed monitoring components already have their own configuration reload
|
|
paths; Traefik watches its file-provider configuration. They are not globally
|
|
opted in. The controller does not react to files in PVCs or changes to external
|
|
services unless a watched ConfigMap or Secret changes.
|
|
|
|
## Verify
|
|
|
|
```sh
|
|
kubectl -n reloader rollout status deployment/reloader-reloader
|
|
kubectl -n reloader logs deployment/reloader-reloader --since=10m
|
|
kubectl -n netbird get deployment netbird-server-deployment \
|
|
-o jsonpath='{.metadata.annotations.reloader\.stakater\.com/auto}'
|
|
```
|
|
|
|
A changed configuration can briefly interrupt a single-replica service, especially
|
|
one using `Recreate`. Installing annotations does not validate the configuration
|
|
or migrate database data. Keep changes to shared Secrets coordinated across consumers.
|
|
|
|
See the [repository README](../README.md) for deployment selection.
|