From 9237ad8ce2cf94f00e742529531b9d0d1bf94251 Mon Sep 17 00:00:00 2001 From: Bryan Frimin Date: Wed, 18 Mar 2026 19:12:06 +0100 Subject: [PATCH] Fix entrypoint to regenerate config when env vars are updated When PROBOD_ENCRYPTION_KEY is set, always run probod-bootstrap to regenerate the config file. This ensures that updated environment variables take effect even when a stale config file exists on a persistent volume (e.g., PVC). Previously, an existing config file would be reused unconditionally, causing env var changes to be ignored on container restart. Signed-off-by: Bryan Frimin --- entrypoint.sh | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/entrypoint.sh b/entrypoint.sh index 6522fd7bb..6dd836cfc 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -4,13 +4,18 @@ set -e # Configuration file path CONFIG_FILE="${CONFIG_FILE:-/etc/probod/config.yml}" -# Check if config file already exists (e.g., mounted from ConfigMap) -if [ -f "$CONFIG_FILE" ]; then +# If bootstrap env vars are set, always (re)generate the config from them. +# This ensures that updated env vars take effect even when a stale config +# file exists on a persistent volume. When no env vars are present, fall +# back to an existing config file (e.g., mounted from a ConfigMap). +if [ -n "$PROBOD_ENCRYPTION_KEY" ]; then + echo "Generating configuration file from environment variables at: $CONFIG_FILE" + probod-bootstrap -output "$CONFIG_FILE" +elif [ -f "$CONFIG_FILE" ]; then echo "Using existing configuration file at: $CONFIG_FILE" else - echo "Generating configuration file from environment variables at: $CONFIG_FILE" - # Generate configuration from environment variables - probod-bootstrap -output "$CONFIG_FILE" + echo "Error: no bootstrap env vars set and no config file found at $CONFIG_FILE" >&2 + exit 1 fi # Execute probod with the generated config