Keystore hot-reload

Keystore hot-reload #

Rotating a secret no longer restarts the node. ${keystore:...} references re-resolve into the running configuration on demand: console edits trigger the reload themselves, and out-of-band changes (a CLI edit, a replaced mounted Secret) are one call away.

curl -X POST http://127.0.0.1:28000/_node/_local/keystore/_reload \
  -H 'Authorization: Bearer pz_bootstrap_key'

The answer says exactly what happened — key names only, values stay write-only:

{
  "entries": 3,
  "read_only": false,
  "references": 2,
  "changed": ["node.embedding.endpoints", "catalog.join_token"],
  "unchanged": 0,
  "failed": []
}

A rotated embedding API key applies to the next inference call; a rotated catalog.join_token to the next join attempt. A reference whose entry disappeared keeps its running value and lands in failed until the entry returns — reload never aborts the node the way a missing entry aborts boot.

The console’s Nodes → (a node) → Keystore tab gained a Reload button with the same report; on a read-only keystore (a CSI-mounted Secret) it is the one control that still applies, which turns “replace the mounted file, hit Reload” into a zero-integration rotation path.

Only values that referenced the keystore hot-apply — pizza.yml itself, environment references, and -E CLI overrides still change at boot. See Keystore for the full semantics.

Calendar September 30, 2026
Edit Edit this page