From 8793fe25d32e1e6057018a0eff75d49acf97adaf Mon Sep 17 00:00:00 2001 From: Sibei Chen Date: Fri, 12 Jun 2026 14:42:08 +0800 Subject: [PATCH] Restart app on Doppler config changes via doppler run --watch App-only secrets now rotate with just a Doppler update: the CLI restarts the JVM in place when the prd config changes. nginx/p12-coupled secrets still require an ansible re-converge, as documented in the entrypoint. Co-Authored-By: Claude Fable 5 --- entrypoint.sh | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/entrypoint.sh b/entrypoint.sh index 8030ea6..cdc374c 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -5,4 +5,9 @@ set -eu # --fallback keeps restarts working if api.doppler.com is briefly unreachable: doppler # itself writes/refreshes this encrypted file on every successful fetch (it need not # pre-exist) and only reads it when the API is unreachable. -exec doppler run --fallback /opt/api-server/doppler-fallback.json -- java -jar api-server.jar +# --watch (BETA) restarts the JVM in place whenever the Doppler config changes, so +# app-only secrets rotate without touching the box. Batch multi-secret rotations into +# one `doppler secrets set K1=… K2=…` call (each change event = one restart), and +# rotate nginx/p12-coupled secrets (proxy secret, keystore password) via an ansible +# re-converge instead — a watch restart alone would leave nginx/p12 out of sync. +exec doppler run --watch --fallback /opt/api-server/doppler-fallback.json -- java -jar api-server.jar