Files
homelab/reloader/README.md
T
forust 5c8bc15e60
renovate-ci / validate-renovate (push) Skipped
ci / lint-compose (push) Successful in 10s
ci / lint-actionlint (push) Successful in 7s
ci / lint-shellcheck (push) Successful in 9s
ci / lint-prettier (push) Successful in 19s
ci / lint-ruff (push) Successful in 7s
ci / lint-yaml (push) Successful in 10s
ci / lint-dockerfiles (push) Successful in 6s
ci / validate (push) Successful in 6s
ci / build (push) Skipped
ci / lint-compose (pull_request) Successful in 10s
ci / lint-actionlint (pull_request) Successful in 5s
ci / lint-shellcheck (pull_request) Successful in 8s
ci / lint-prettier (pull_request) Successful in 16s
ci / lint-ruff (pull_request) Successful in 7s
ci / lint-yaml (pull_request) Successful in 10s
ci / lint-dockerfiles (pull_request) Successful in 7s
ci / validate (pull_request) Successful in 7s
ci / build (pull_request) Skipped
renovate-ci / validate-renovate (pull_request) Successful in 9s
docs(reloader): describe workload opt-in and reload policy
2026-10-06 16:14:04 +02:00

2.4 KiB

Reloader

Restarts opted-in workloads when the ConfigMaps or Secrets they consume change. The deploy workflow upgrades the reloader Helm release in namespace reloader; k8s/active enables it. The chart version is pinned in deploy-lib.sh.

Workload integration

Put this annotation on the Deployment or StatefulSet metadata:

metadata:
  annotations:
    reloader.stakater.com/auto: "true"

The annotation belongs to the workload, not spec.template.metadata. Reloader discovers references in environment variables and mounted volumes. This covers startup-only settings and ConfigMaps or Secrets mounted with subPath. See the upstream usage guide.

The application manifests opt in 28 workloads, including AdGuard's TLS files, NetBird, both NetBox processes, EDU bots, and the password-protected Valkey servers. Inactive services have the same annotations ready for later activation.

Controller policy

The controller watches all namespaces but only restarts annotated workloads. It uses the annotations reload strategy, so changes trigger a pod-template annotation rather than injecting extra environment variables.

Jobs and CronJobs are excluded: their next execution reads current configuration. PostgreSQL is intentionally not opted in. Its password variables and init scripts apply to first initialization; restarting an existing database does not rotate roles or rerun those scripts. Rotate database credentials with SQL and update the clients' Secrets together.

Helm-managed monitoring components already have their own configuration reload paths; Traefik watches its file-provider configuration. They are not globally opted in. The controller does not react to files in PVCs or changes to external services unless a watched ConfigMap or Secret changes.

Verify

kubectl -n reloader rollout status deployment/reloader-reloader
kubectl -n reloader logs deployment/reloader-reloader --since=10m
kubectl -n netbird get deployment netbird-server-deployment \
  -o jsonpath='{.metadata.annotations.reloader\.stakater\.com/auto}'

A changed configuration can briefly interrupt a single-replica service, especially one using Recreate. Installing annotations does not validate the configuration or migrate database data. Keep changes to shared Secrets coordinated across consumers.

See the repository README for deployment selection.