Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
You can apply changed Kubernetes Secret or ConfigMap values to a running Go service without restarting its pods by having the service watch the Kubernetes API and reconcile new configuration in-process. The mamori Kubernetes provider supports this with k8s-secret:// and k8s-cm:// sources; your application must still update resources such as database pools or TLS clients when the configuration-change callback runs.
Why changing a ConfigMap or Secret may not change a running process
A Kubernetes object can change while the process using its value continues with the configuration it received earlier. In particular, a container’s environment is established when the process starts. Kubernetes documents that ConfigMaps consumed as environment variables are not updated automatically and require a pod restart: ConfigMaps.
Mounted ConfigMap volumes work differently: Kubernetes eventually updates projected data, but propagation takes time, and the application must notice and read the new contents. A ConfigMap mounted with subPath does not receive updates. Neither approach, by itself, guarantees that an application’s already-created clients or other resources are reconfigured.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsHow mamori applies updates without restarting pods
mamori’s Kubernetes provider reads Secrets and ConfigMaps through client-go and watches the Kubernetes API. It emits changes for Added and Modified events. If the server-side watch ends while its context remains active, the provider re-lists and starts another watch; this is not polling. That reconnection behavior is not a guarantee of instantaneous delivery, a maximum recovery time, or zero missed updates. See the Kubernetes provider documentation.
#1 Best Overall
On an update, mamori validates the complete configuration and atomically swaps in the new snapshot only when it is valid. That protects the application from adopting a partially applied or invalid configuration, but it does not automatically reconfigure every dependent library. The application’s callback needs to do that work. The mamori introduction describes the watch and reconciliation flow.
Choose the update path that fits your application
| Approach | How changes reach the application | What to account for |
|---|---|---|
| Environment variables | Values are injected when the container starts. | Kubernetes says ConfigMap values consumed as environment variables are not automatically updated; a pod restart is required. See the ConfigMaps documentation. |
| Mounted ConfigMap files | Kubernetes eventually refreshes projected volume data. | Propagation is delayed by kubelet synchronization and caching; the application must notice and reread the data. A subPath mount does not receive updates. See the ConfigMaps documentation. |
| In-process mamori API watch | The running Go process watches the API and reconciles changed objects. | Requires Kubernetes API connectivity and appropriate permissions. The application callback must safely update dependent resources. See the provider documentation and mamori introduction. |
An API watch is useful when an application is designed to adopt selected settings live. A controlled rollout can be a better choice when the change should coincide with a new application version or when a dependency cannot safely be reconfigured at runtime.
Rank #2
Install and configure the Kubernetes provider
The mamori documentation specifies Go 1.26 or newer and installs the Kubernetes provider as a separate module. Because Go requirements can change, check the current project documentation before adopting the version requirement. The provider package is github.com/xavidop/mamori/providers/k8s; its Go package reference identifies Secret values as sensitive and ConfigMap values as non-sensitive.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallImport the core mamori package and blank-import the provider package so its URI schemes are registered. Define configuration fields with source tags, then create a watcher and keep it alive for the service lifetime:
import (
"context"
"log"
"time"
"github.com/xavidop/mamori"
"github.com/xavidop/mamori/secret"
_ "github.com/xavidop/mamori/providers/k8s"
)
type Config struct {
DBPassword secret.String `source:"k8s-secret://prod/db-creds#password"`
LogLevel string `source:"k8s-cm://prod/app-config#log_level"`
Timeout time.Duration `source:"k8s-cm://prod/app-config#request_timeout"`
}
func startConfigWatch(ctx context.Context) error {
watcher, err := mamori.Watch[Config](ctx, func(next Config) {
// Apply the validated snapshot to application-owned resources.
// For example, update logging settings or safely rotate a client.
log.Printf("configuration changed; log level is %s", next.LogLevel)
})
if err != nil {
return err
}
_ = watcher // Retain the watcher for the lifetime of the service.
return nil
}
The snippet illustrates source tags and the watch lifecycle; adapt the callback to the API provided by your application and mamori version. Do not treat a successful configuration swap as proof that a database driver, TLS listener, or other dependency has applied its new settings.
Secret and ConfigMap URI forms
k8s-secret://<namespace>/<name>#<key>selects one Secret data key.k8s-cm://<namespace>/<name>#<key>selects one ConfigMap key. ConfigMap lookup checksdataand thenbinaryData.- Omitting
#<key>resolves the object’s entire data map as a JSON object. See the provider URI documentation.
For credentials, use a sensitive type such as secret.String, rather than an ordinary string where the application’s configuration model supports that distinction. mamori’s sensitivity labels are useful defense in depth; they do not encrypt data stored by Kubernetes or change what the pod is authorized to read.
Rank #4
Make the callback safe for live changes
Use the callback to update only what can be changed safely at runtime. A log-level change may be a straightforward in-process update. A database credential change may require constructing a replacement pool, verifying it can connect, switching new work to it, and draining the old pool. The right sequence depends on the client library and application; mamori’s configuration swap alone does not provide resource rotation or rollback.
For certificates, verify that the TLS component actually reloads the new certificate and key. Some components need a new configuration object or listener, while others provide their own reload mechanism. If a new resource cannot be initialized or validated, retain the working resource and report the failure rather than replacing it with an unusable one.
Plan an operational fallback as well: monitor callback and validation errors, and use a controlled rollout when safe live adoption cannot be established for a particular setting. The Kubernetes watch depends on API connectivity and permissions, so it should not be treated as a reason to remove normal service health checks or recovery procedures.
Grant only the Kubernetes permissions the service needs
The pod’s identity must be permitted to read the specific Secrets and ConfigMaps it watches in the relevant namespace. Scope access narrowly and follow Kubernetes’ least-privilege guidance; avoid granting broad Secret-read access merely to make configuration loading convenient. Kubernetes recommends encryption at rest and least-privilege RBAC in its Secrets documentation.
Secret values encoded as base64 are not thereby encrypted. Kubernetes’ documentation warns that base64 “does NOT provide any useful level of confidentiality” in its TLS Secret example. Treat access to Secret objects as access to the underlying credentials, and apply appropriate storage and access controls.
Keep the watch lifecycle tied to the service
Use a context whose lifetime matches the service and cancel it during shutdown so the watch can stop. Close the provider when the application owns its lifecycle; the provider documentation says Close is idempotent and terminal, and that a provider-created client releases its idle connections. See the provider lifecycle documentation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

