Skip to content

Reloading configuration

SIGHUP reloads configuration without dropping connections:

Terminal window
kill -HUP $(pidof curral)
docker compose kill -s HUP curral
Reloads on SIGHUP Needs a restart
users file (users, API keys, identities) catalog file
policy files (.rego and data) flags and environment
row filters (--row-filters)
TLS certificate
audit log (reopened)
  • Invalid files are rejected and the previous version stays in effect; the error goes to the log.
  • Atomic swap: in-flight requests finish with the version they started with.
  • Password cache is dropped, so removed users and changed passwords take effect immediately.
  • Tracking: each attempt produces a config_reload audit event with the new policy_sha256 or the error, and counts in curral_config_reloads_total.

The catalog is mounted and locked at startup, which is why it cannot change at runtime.