Skip to content

feat(composer): auto-refresh connectors when composer-level config changes #148

Description

Problem

When composer-level settings change (e.g. image_resources, base_deployment, Docker network_mode, Swarm resources), currently deployed connectors are not updated automatically. The existing contract_hash mechanism only detects platform-side config changes (from OpenCTI/OpenAEV API), not local composer configuration changes.

Users must manually delete deployments and let the composer recreate them — impractical in bulk across production instances.

Related: #39, #53

Current workaround

Delete all managed deployments in bulk and let the composer recreate them:

# Kubernetes
kubectl delete deployments -l opencti-manager=<manager-id> -n <namespace>

# Docker
docker rm -f $(docker ps -aq --filter "label=opencti-manager=<manager-id>")

# Docker Swarm
docker service rm $(docker service ls --filter "label=opencti-manager=<manager-id>" -q)

Proposed solution: Composer Config Hash

Introduce a COMPOSER_CONFIG_HASH that captures orchestrator-level settings. Store it in each deployed container. On each orchestration cycle, compare it against the current computed hash — if they differ, trigger refresh().

Implementation outline

  1. Compute a SHA-256 hash of each orchestrator's config struct:

    • Kubernetes: image_resources, base_deployment, base_deployment_json, image_pull_policy
    • Docker: network_mode, extra_hosts, dns, privileged, cap_add, etc.
    • Swarm: network, extra_hosts, resources, placement_constraints, etc.
  2. Store the hash in deployed containers:

    • Kubernetes: as a deployment annotation (consistent with OPENCTI_CONFIG_HASH)
    • Docker/Swarm/Portainer: as a container env variable or label
  3. Compare each orchestration cycle in orchestrate_existing():

    let current_composer_hash = container.extract_composer_hash();
    let expected_composer_hash = compute_composer_hash(&settings);
    if current_composer_hash != expected_composer_hash {
        orchestrator.refresh(connector).await;
    }
  4. Backward compatibility: Containers without the hash (deployed before this feature) are treated as "needs refresh" — providing a one-time automatic rollout of new config on upgrade.

Benefits

  • Fully automatic — no manual intervention or API needed
  • Works for all orchestrators consistently
  • Leverages the existing refresh() mechanism
  • After upgrading the composer, all existing connectors are refreshed once (applying new config like memory limits)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    featureType: new feature or capability (feat:).needs triageNeeds triage from the Filigran product team.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions