docs(reloader): describe workload opt-in and reload policy
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 7s
ci / lint-shellcheck (push) Successful in 9s
ci / lint-prettier (push) Successful in 19s
ci / lint-ruff (push) Successful in 7s
ci / lint-yaml (push) Successful in 10s
ci / lint-dockerfiles (push) Successful in 6s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 10s
ci / lint-actionlint (pull_request) Successful in 5s
ci / lint-shellcheck (pull_request) Successful in 8s
ci / lint-prettier (pull_request) Successful in 16s
ci / lint-ruff (pull_request) Successful in 7s
ci / lint-yaml (pull_request) Successful in 10s
ci / lint-dockerfiles (pull_request) Successful in 7s
ci / validate (pull_request) Successful in 7s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 9s
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 7s
ci / lint-shellcheck (push) Successful in 9s
ci / lint-prettier (push) Successful in 19s
ci / lint-ruff (push) Successful in 7s
ci / lint-yaml (push) Successful in 10s
ci / lint-dockerfiles (push) Successful in 6s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 10s
ci / lint-actionlint (pull_request) Successful in 5s
ci / lint-shellcheck (pull_request) Successful in 8s
ci / lint-prettier (pull_request) Successful in 16s
ci / lint-ruff (pull_request) Successful in 7s
ci / lint-yaml (pull_request) Successful in 10s
ci / lint-dockerfiles (pull_request) Successful in 7s
ci / validate (pull_request) Successful in 7s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 9s
This commit is contained in:
1 parent
3c4732ae20
commit
5c8bc15e60
3 files changed
+66
-8
No files matched your search
+50
-7
@@ -1,13 +1,56 @@
|
||||
# Reloader
|
||||
|
||||
Helm settings for restarting workloads when referenced configuration changes.
|
||||
Restarts opted-in workloads when the ConfigMaps or Secrets they consume change.
|
||||
The deploy workflow upgrades the `reloader` Helm release in namespace `reloader`;
|
||||
`k8s/active` enables it. The chart version is pinned in `deploy-lib.sh`.
|
||||
|
||||
The deploy library knows the `reloader` Helm release and the values file here,
|
||||
but there is no `k8s/active` marker, so it is not upgraded automatically.
|
||||
## Workload integration
|
||||
|
||||
Reloader only acts on workloads configured for it. A ConfigMap mounted with
|
||||
`subPath` does not update inside an existing container by itself. Verify that the
|
||||
application restarted after a configuration change rather than assuming an
|
||||
apply updated the running process.
|
||||
Put this annotation on the Deployment or StatefulSet metadata:
|
||||
|
||||
```yaml
|
||||
metadata:
|
||||
annotations:
|
||||
reloader.stakater.com/auto: "true"
|
||||
```
|
||||
|
||||
The annotation belongs to the workload, not `spec.template.metadata`.
|
||||
Reloader discovers references in environment variables and mounted volumes.
|
||||
This covers startup-only settings and ConfigMaps or Secrets mounted with `subPath`.
|
||||
See the [upstream usage guide](https://github.com/stakater/Reloader/blob/v1.4.22/README.md#usage).
|
||||
|
||||
The application manifests opt in 28 workloads, including AdGuard's TLS files,
|
||||
NetBird, both NetBox processes, EDU bots, and the password-protected Valkey servers.
|
||||
Inactive services have the same annotations ready for later activation.
|
||||
|
||||
## Controller policy
|
||||
|
||||
The controller watches all namespaces but only restarts annotated workloads.
|
||||
It uses the `annotations` reload strategy, so changes trigger a pod-template
|
||||
annotation rather than injecting extra environment variables.
|
||||
|
||||
Jobs and CronJobs are excluded: their next execution reads current configuration.
|
||||
PostgreSQL is intentionally not opted in. Its password variables and init scripts
|
||||
apply to first initialization; restarting an existing database does not rotate
|
||||
roles or rerun those scripts. Rotate database credentials with SQL and update the
|
||||
clients' Secrets together.
|
||||
|
||||
Helm-managed monitoring components already have their own configuration reload
|
||||
paths; Traefik watches its file-provider configuration. They are not globally
|
||||
opted in. The controller does not react to files in PVCs or changes to external
|
||||
services unless a watched ConfigMap or Secret changes.
|
||||
|
||||
## Verify
|
||||
|
||||
```sh
|
||||
kubectl -n reloader rollout status deployment/reloader-reloader
|
||||
kubectl -n reloader logs deployment/reloader-reloader --since=10m
|
||||
kubectl -n netbird get deployment netbird-server-deployment \
|
||||
-o jsonpath='{.metadata.annotations.reloader\.stakater\.com/auto}'
|
||||
```
|
||||
|
||||
A changed configuration can briefly interrupt a single-replica service, especially
|
||||
one using `Recreate`. Installing annotations does not validate the configuration
|
||||
or migrate database data. Keep changes to shared Secrets coordinated across consumers.
|
||||
|
||||
See the [repository README](../README.md) for deployment selection.
|
||||
Reference in new issue
Block a user