# Reloader Restarts opted-in workloads when the ConfigMaps or Secrets they consume change. The deploy workflow upgrades the `reloader` Helm release in namespace `reloader`; `k8s/active` enables it. The chart version is pinned in `deploy-lib.sh`. ## Workload integration Put this annotation on the Deployment or StatefulSet metadata: ```yaml metadata: annotations: reloader.stakater.com/auto: "true" ``` The annotation belongs to the workload, not `spec.template.metadata`. Reloader discovers references in environment variables and mounted volumes. This covers startup-only settings and ConfigMaps or Secrets mounted with `subPath`. See the [upstream usage guide](https://github.com/stakater/Reloader/blob/v1.4.22/README.md#usage). The application manifests opt in 28 workloads, including AdGuard's TLS files, NetBird, both NetBox processes, EDU bots, and the password-protected Valkey servers. Inactive services have the same annotations ready for later activation. ## Controller policy The controller watches all namespaces but only restarts annotated workloads. It uses the `annotations` reload strategy, so changes trigger a pod-template annotation rather than injecting extra environment variables. Jobs and CronJobs are excluded: their next execution reads current configuration. PostgreSQL is intentionally not opted in. Its password variables and init scripts apply to first initialization; restarting an existing database does not rotate roles or rerun those scripts. Rotate database credentials with SQL and update the clients' Secrets together. Helm-managed monitoring components already have their own configuration reload paths; Traefik watches its file-provider configuration. They are not globally opted in. The controller does not react to files in PVCs or changes to external services unless a watched ConfigMap or Secret changes. ## Verify ```sh kubectl -n reloader rollout status deployment/reloader-reloader kubectl -n reloader logs deployment/reloader-reloader --since=10m kubectl -n netbird get deployment netbird-server-deployment \ -o jsonpath='{.metadata.annotations.reloader\.stakater\.com/auto}' ``` A changed configuration can briefly interrupt a single-replica service, especially one using `Recreate`. Installing annotations does not validate the configuration or migrate database data. Keep changes to shared Secrets coordinated across consumers. See the [repository README](../README.md) for deployment selection.