Keystore hot-reload #
Rotating a secret no longer restarts the node. ${keystore:...}
references re-resolve into the running configuration on demand: console
edits trigger the reload themselves, and out-of-band changes (a CLI
edit, a replaced mounted Secret) are one call away.
curl -X POST http://127.0.0.1:28000/_node/_local/keystore/_reload \
-H 'Authorization: Bearer pz_bootstrap_key'
The answer says exactly what happened — key names only, values stay write-only:
{
"entries": 3,
"read_only": false,
"references": 2,
"changed": ["node.embedding.endpoints", "catalog.join_token"],
"unchanged": 0,
"failed": []
}
A rotated embedding API key applies to the next inference call; a
rotated catalog.join_token to the next join attempt. A reference
whose entry disappeared keeps its running value and lands in failed
until the entry returns — reload never aborts the node the way a
missing entry aborts boot.
The console’s Nodes → (a node) → Keystore tab gained a Reload button with the same report; on a read-only keystore (a CSI-mounted Secret) it is the one control that still applies, which turns “replace the mounted file, hit Reload” into a zero-integration rotation path.
Only values that referenced the keystore hot-apply — pizza.yml
itself, environment references, and -E CLI overrides still change at
boot. See
Keystore for the
full semantics.