Skip to content

Embedded mode uses kill -9 — no graceful shutdown or zero-downtime reload #11

Description

@gsmlg

Problem

Caddy.Server.Embedded terminates the Caddy process with SIGKILL:

  • cleanup/2 (lib/caddy/server/embedded.ex:261) — kill -9 on the port OS pid
  • cleanup_pidfile/0 (lib/caddy/server/embedded.ex:246) — kill -9 on stale pidfile pid

Impact

  • In-flight connections are dropped on every stop/restart
  • Caddy's graceful shutdown is skipped (lock release, cert maintenance cleanup)
  • Caddy.restart_server/0 is stop-then-start, so every reconfigure in embedded mode incurs downtime

Fix

  1. Use SIGTERM (or POST /stop via the Admin API) with a kill-timeout fallback to SIGKILL
  2. Prefer graceful config swaps via /load for reconfiguration instead of full process restarts — restart should be the exception, not the reload mechanism

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions