Problem
When composer-level settings change (e.g. image_resources, base_deployment, Docker network_mode, Swarm resources), currently deployed connectors are not updated automatically. The existing contract_hash mechanism only detects platform-side config changes (from OpenCTI/OpenAEV API), not local composer configuration changes.
Users must manually delete deployments and let the composer recreate them — impractical in bulk across production instances.
Related: #39, #53
Current workaround
Delete all managed deployments in bulk and let the composer recreate them:
# Kubernetes
kubectl delete deployments -l opencti-manager=<manager-id> -n <namespace>
# Docker
docker rm -f $(docker ps -aq --filter "label=opencti-manager=<manager-id>")
# Docker Swarm
docker service rm $(docker service ls --filter "label=opencti-manager=<manager-id>" -q)
Proposed solution: Composer Config Hash
Introduce a COMPOSER_CONFIG_HASH that captures orchestrator-level settings. Store it in each deployed container. On each orchestration cycle, compare it against the current computed hash — if they differ, trigger refresh().
Implementation outline
-
Compute a SHA-256 hash of each orchestrator's config struct:
- Kubernetes:
image_resources, base_deployment, base_deployment_json, image_pull_policy
- Docker:
network_mode, extra_hosts, dns, privileged, cap_add, etc.
- Swarm:
network, extra_hosts, resources, placement_constraints, etc.
-
Store the hash in deployed containers:
- Kubernetes: as a deployment annotation (consistent with
OPENCTI_CONFIG_HASH)
- Docker/Swarm/Portainer: as a container env variable or label
-
Compare each orchestration cycle in orchestrate_existing():
let current_composer_hash = container.extract_composer_hash();
let expected_composer_hash = compute_composer_hash(&settings);
if current_composer_hash != expected_composer_hash {
orchestrator.refresh(connector).await;
}
-
Backward compatibility: Containers without the hash (deployed before this feature) are treated as "needs refresh" — providing a one-time automatic rollout of new config on upgrade.
Benefits
- Fully automatic — no manual intervention or API needed
- Works for all orchestrators consistently
- Leverages the existing
refresh() mechanism
- After upgrading the composer, all existing connectors are refreshed once (applying new config like memory limits)
Problem
When composer-level settings change (e.g.
image_resources,base_deployment, Dockernetwork_mode, Swarmresources), currently deployed connectors are not updated automatically. The existingcontract_hashmechanism only detects platform-side config changes (from OpenCTI/OpenAEV API), not local composer configuration changes.Users must manually delete deployments and let the composer recreate them — impractical in bulk across production instances.
Related: #39, #53
Current workaround
Delete all managed deployments in bulk and let the composer recreate them:
Proposed solution: Composer Config Hash
Introduce a
COMPOSER_CONFIG_HASHthat captures orchestrator-level settings. Store it in each deployed container. On each orchestration cycle, compare it against the current computed hash — if they differ, triggerrefresh().Implementation outline
Compute a SHA-256 hash of each orchestrator's config struct:
image_resources,base_deployment,base_deployment_json,image_pull_policynetwork_mode,extra_hosts,dns,privileged,cap_add, etc.network,extra_hosts,resources,placement_constraints, etc.Store the hash in deployed containers:
OPENCTI_CONFIG_HASH)Compare each orchestration cycle in
orchestrate_existing():Backward compatibility: Containers without the hash (deployed before this feature) are treated as "needs refresh" — providing a one-time automatic rollout of new config on upgrade.
Benefits
refresh()mechanism