Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion entrypoint.sh
Original file line number Diff line number Diff line change
Expand Up @@ -5,4 +5,9 @@ set -eu
# --fallback keeps restarts working if api.doppler.com is briefly unreachable: doppler
# itself writes/refreshes this encrypted file on every successful fetch (it need not
# pre-exist) and only reads it when the API is unreachable.
exec doppler run --fallback /opt/api-server/doppler-fallback.json -- java -jar api-server.jar
# --watch (BETA) restarts the JVM in place whenever the Doppler config changes, so
# app-only secrets rotate without touching the box. Batch multi-secret rotations into
# one `doppler secrets set K1=… K2=…` call (each change event = one restart), and
# rotate nginx/p12-coupled secrets (proxy secret, keystore password) via an ansible
# re-converge instead — a watch restart alone would leave nginx/p12 out of sync.
exec doppler run --watch --fallback /opt/api-server/doppler-fallback.json -- java -jar api-server.jar
Loading