Skip to content

Restart app on Doppler config changes via doppler run --watch - #143

Merged
SibeiC merged 1 commit into
masterfrom
feat/doppler-watch
Jun 12, 2026
Merged

SibeiC merged 1 commit into
masterfrom
feat/doppler-watch

Conversation

@SibeiC

@SibeiC SibeiC commented Jun 12, 2026

Copy link
Copy Markdown
Owner

Adds --watch (BETA) to doppler run in the entrypoint: the CLI holds a connection to Doppler and restarts the JVM in place whenever the prd config changes, so app-only secrets (Mongo URI, R2 keys, GitHub tokens, mail creds) rotate with nothing but a Doppler update — same brief 502 window as a deploy.

Caveats documented in the entrypoint comment:

  • batch multi-secret rotations into a single doppler secrets set K1=… K2=… call (each change event triggers one restart)
  • nginx/p12-coupled secrets (APP_MTLS_PROXY_SECRET, APP_TLS_KEYSTORE_PASSWORD) must still go through an ansible re-converge — a watch restart alone would leave nginx/the keystore out of sync

Verified locally that --watch --fallback combine cleanly and the wrapped process runs and exits normally (doppler CLI v3.76.0).

🤖 Generated with Claude Code

App-only secrets now rotate with just a Doppler update: the CLI restarts
the JVM in place when the prd config changes. nginx/p12-coupled secrets
still require an ansible re-converge, as documented in the entrypoint.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 12, 2026 06:43

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the container entrypoint to run the Spring Boot JAR under doppler run --watch so the JVM is restarted in-place when Doppler prd secrets/config change, allowing runtime secret rotation without a redeploy.

Changes:

  • Add --watch (beta) to the doppler run wrapper in entrypoint.sh.
  • Document operational caveats around batching secret updates and handling nginx/PKCS#12-coupled secrets.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread entrypoint.sh
# one `doppler secrets set K1=… K2=…` call (each change event = one restart), and
# rotate nginx/p12-coupled secrets (proxy secret, keystore password) via an ansible
# re-converge instead — a watch restart alone would leave nginx/p12 out of sync.
exec doppler run --watch --fallback /opt/api-server/doppler-fallback.json -- java -jar api-server.jar
@github-actions

Copy link
Copy Markdown

Qodana for JVM

It seems all right 👌

No new problems were found according to the checks applied

💡 Qodana analysis was run in the pull request mode: only the changed files were checked
☁️ View the detailed Qodana report

Contact Qodana team

Contact us at qodana-support@jetbrains.com

@SibeiC
SibeiC merged commit 853bffa into master Jun 12, 2026
11 checks passed
@SibeiC
SibeiC deleted the feat/doppler-watch branch June 12, 2026 06:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants