Enable Reloader secret watching, scope existing auto to configmap-only (#326) (#339)

## Why

The re-keyed internal `unkin.net` intermediate broke CA consumers (CNPG->RGW backups, subPath/startup-cached CA mounts) and needed manual pod restarts, because Reloader was deployed with `ignoreSecrets: true` and could not restart on the `vault-ca-cert` Secret. Enabling secret watching naively is unsafe: many workloads carry the generic `reloader.stakater.com/auto`, and the estate rotates numerous Secrets via Vault/VSO — those would restart on every rotation. This enables secret watching but scopes existing `auto` to ConfigMaps, making secret-reload opt-in per Secret.

## Changes

- Set `reloader.ignoreSecrets: false` (au-syd1 reloader-system values) so Secrets are watched.
- Convert every generic `reloader.stakater.com/auto: "true"` to the ConfigMap-only `configmap.reloader.stakater.com/auto: "true"` — 22 annotations across 19 files. Existing ConfigMap-reload behaviour is preserved; Vault/VSO Secret rotations no longer restart these workloads.
- Add explicit `secret.reloader.stakater.com/reload: "vault-ca-cert"` to the CA consumers that mount the CA and carry a Reloader annotation: `artifactapi/api`, `cephrgw-operator`, `puppetserver-master`, `puppetserver-compiler`, `litellm`, `logarchiver`.
- Add `secret.reloader.stakater.com/reload: "kanidm-tls"` so kanidm rolls when cert-manager renews its leaf.
- Add `docs/ca-rotation.md` runbook (indexed in `docs/README.md`).

## Safety review (secret-only / CA workloads)

`vault-ca-cert` is a plain reflected Secret that bootstraps Vault trust (not VSO-rotated; changes only on intermediate re-key). `kanidm-tls` is a cert-manager leaf. Everything else mounted (`environment`, `*-credentials`, `eyaml-keys`, `puppetboard-secrets`, `s3-credentials`, `nats-auth`, `clickhouse-credentials`, `woodpecker-*`) is VSO/CNPG Vault-rotated and deliberately excluded.

- `cephrgw-operator` — mounts only Secrets (`cephrgw-credentials` VSO + `vault-ca-cert`), no ConfigMap. Its old comment said "restart when the credentials Secret rotates"; `cephrgw-credentials` is VSO so that is now excluded, and reload is scoped to `vault-ca-cert` only. Comment updated.
- `nats` (logging) — old comment "Roll the StatefulSet when nats-auth changes"; `nats-auth` is VSO, so this is now ConfigMap-only (deliberately no roll on rotation). Comment updated. Same for the vector agent/aggregator/vm-ingest (VSO `nats-auth`/`clickhouse-credentials`).
- `artifactapi/ui` — mounts neither a ConfigMap nor a Secret; its `auto` was already a no-op. Left as ConfigMap-only.
- `puppetdb` / `puppetboard` — mount a ConfigMap plus VSO Secrets (postgres creds / puppetboard-secrets); ConfigMap-only is correct, no secret reload added.

CA consumers that mount `vault-ca-cert` but have **no** Reloader annotation (CRD-managed or startup-cached) are documented in `docs/ca-rotation.md` for manual restart rather than annotated here: `grafana`, `observability/vmagent`, `paperclip`, `argocd-repo-server`, plus CNPG clusters (`kubectl cnpg restart`).

## Notes / coordination

- Annotations left in their existing location (some sit on the pod template, e.g. `litellm`, `puppetdb`; Reloader reads controller-level metadata — placement unchanged from before, no regression).
- Touches `apps/overlays/au-syd1/logging/values-vector-*.yaml`, which overlap open PR #320 (Tier-2 Vector pipelines) — only the one-line reloader annotation is changed here.

## Validation

- `make kubeconform` — touched overlays (reloader-system, logging, woodpecker, authentik) valid; only the known-unrelated cattle-system rancher chart kubeVersion failure remains.
- `uvx pre-commit run --all-files` — all hooks pass.

Closes #326

---------

Co-authored-by: Ben Vincent <neotheo@gmail.com>
Reviewed-on: #339
Co-authored-by: Ben Vincent <ben@unkin.net>
Co-committed-by: Ben Vincent <ben@unkin.net>
This commit was merged in pull request #339.
This commit is contained in:
2026-08-08 19:35:31 +10:00
committed by BenVincent
parent ca5e29e685
commit ba7a1a9509
22 changed files with 105 additions and 25 deletions
+1 -1
View File
@@ -12,7 +12,7 @@ spec:
template:
metadata:
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
labels:
app: age-api
spec:
+2 -1
View File
@@ -5,7 +5,8 @@ metadata:
name: api
namespace: artifactapi
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "vault-ca-cert"
spec:
selector:
matchLabels:
+1 -1
View File
@@ -5,7 +5,7 @@ metadata:
name: ui
namespace: artifactapi
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
spec:
selector:
matchLabels:
+4 -2
View File
@@ -7,8 +7,10 @@ metadata:
labels:
app.kubernetes.io/name: cephrgw-operator
annotations:
# Restart the operator when the credentials Secret rotates.
reloader.stakater.com/auto: "true"
# Restart on internal CA rotation only; cephrgw-credentials is Vault-rotated
# (VSO) and deliberately excluded so routine key rotation causes no restart.
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "vault-ca-cert"
spec:
replicas: 1
selector:
+1 -1
View File
@@ -5,7 +5,7 @@ metadata:
name: encapi
namespace: encapi
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
spec:
replicas: 2
selector:
+2 -1
View File
@@ -5,7 +5,8 @@ metadata:
name: kanidm
namespace: kanidm
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "kanidm-tls"
labels:
app.kubernetes.io/name: kanidm
app.kubernetes.io/instance: kanidm
+2 -1
View File
@@ -11,7 +11,8 @@ spec:
template:
metadata:
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "vault-ca-cert"
labels:
app: litellm
spec:
@@ -10,7 +10,8 @@ metadata:
name: logarchiver
namespace: logging
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "vault-ca-cert"
labels:
app.kubernetes.io/name: logarchiver
app.kubernetes.io/component: archiver
+1 -1
View File
@@ -5,7 +5,7 @@ metadata:
name: pdbmux
namespace: pdbmux
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
spec:
replicas: 2
selector:
+1 -1
View File
@@ -21,7 +21,7 @@ spec:
template:
metadata:
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
labels:
app.kubernetes.io/component: puppetboard
app.kubernetes.io/instance: puppetserver
+1 -1
View File
@@ -20,7 +20,7 @@ spec:
template:
metadata:
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
labels:
app.kubernetes.io/component: puppetdb
app.kubernetes.io/instance: puppetserver
@@ -2,7 +2,8 @@ apiVersion: apps/v1
kind: Deployment
metadata:
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "vault-ca-cert"
labels:
app.kubernetes.io/component: puppetserver-compilers
app.kubernetes.io/instance: puppetserver
@@ -2,7 +2,8 @@ apiVersion: apps/v1
kind: Deployment
metadata:
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
secret.reloader.stakater.com/reload: "vault-ca-cert"
labels:
app.kubernetes.io/component: puppetserver
app.kubernetes.io/instance: puppetserver
@@ -20,7 +21,7 @@ spec:
template:
metadata:
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
labels:
app.kubernetes.io/component: puppetserver
app.kubernetes.io/instance: puppetserver
+2 -2
View File
@@ -75,7 +75,7 @@ global:
server:
replicas: 3
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
ingress:
enabled: false
resources:
@@ -89,7 +89,7 @@ server:
worker:
replicas: 2
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
resources:
limits:
cpu: "2"
@@ -86,12 +86,13 @@ container:
cpu: "2"
memory: 4Gi
# Roll the StatefulSet when nats-auth changes.
# Roll the StatefulSet on config changes only; nats-auth is Vault-rotated (VSO)
# so it is deliberately not watched here (no restart on routine key rotation).
podTemplate:
merge:
metadata:
annotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
# Config-reloader sidecar image, also through artifactapi.
reloader:
@@ -50,4 +50,4 @@ existingConfigMaps:
- vector-agent-config
workloadResourceAnnotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
@@ -26,7 +26,7 @@ autoscaling:
targetCPUUtilizationPercentage: 70
workloadResourceAnnotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
podLabels:
vector.dev/exclude: "true"
@@ -10,7 +10,7 @@ image:
tag: 0.57.0-distroless-libc
workloadResourceAnnotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
podLabels:
vector.dev/exclude: "true"
@@ -2,7 +2,10 @@
reloader:
autoReloadAll: false
isArgoRollouts: true
ignoreSecrets: true
# Watch Secrets so opt-in secret.reloader.stakater.com/reload works (issue
# #326). Workloads use configmap-only auto by default; Vault/VSO-rotated
# Secrets do NOT trigger restarts unless explicitly named.
ignoreSecrets: false
ignoreConfigMaps: false
ignoreJobs: true
ignoreCronJobs: true
+2 -2
View File
@@ -17,7 +17,7 @@ agent:
persistence:
storageClass: cephrbd-fast-delete
podAnnotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
resources:
requests:
cpu: 50m
@@ -40,7 +40,7 @@ server:
persistentVolume:
storageClass: cephrbd-fast-delete
podAnnotations:
reloader.stakater.com/auto: "true"
configmap.reloader.stakater.com/auto: "true"
ingress:
enabled: true
annotations: