Reloading configuration
SIGHUP reloads configuration without dropping connections:
kill -HUP $(pidof curral)docker compose kill -s HUP curralReloads on SIGHUP |
Needs a restart |
|---|---|
| users file (users, API keys, identities) | catalog file |
policy files (.rego and data) |
flags and environment |
row filters (--row-filters) |
|
| TLS certificate | |
| audit log (reopened) |
- Invalid files are rejected and the previous version stays in effect; the error goes to the log.
- Atomic swap: in-flight requests finish with the version they started with.
- Password cache is dropped, so removed users and changed passwords take effect immediately.
- Tracking: each attempt produces a
config_reloadaudit event with the newpolicy_sha256or the error, and counts incurral_config_reloads_total.
The catalog is mounted and locked at startup, which is why it cannot change at runtime.