Documentation
¶
Overview ¶
Command certreloader watches the bfb-registry server-certificate directory and triggers an nginx graceful reload (SIGHUP via `nginx -s reload`) whenever the mounted certificate changes. cert-manager renews bfb-registry-server-cert -> kubelet syncs the non-subPath Secret volume -> certreloader reloads nginx, so the certificate rotates with no dropped connections.
kubelet updates the mounted directory by atomically swapping the `..data` symlink, so we watch the directory (not a single file) and debounce the burst of events that one swap produces.
Click to show internal directories.
Click to hide internal directories.