跳到正文
FunCoding

搜索

搜索文档、文章、Skill 和 MCP

Config hot reload

How the Gateway applies config snapshots, which changes hot-apply, and which need a restart

Config hot reload

The Gateway applies revisioned config snapshots automatically. Most settings do not need a manual restart. ~/.openclaw/openclaw.json remains the config source, including JSON5, $include, and environment substitutions.

Writes made through the running Gateway publish their committed snapshot directly to the reload owner. They do not wait for a file-watcher event or its debounce window. Runtime consumers keep reading the last successfully applied snapshot until the replacement transaction commits. The log records the accepted source revision and whether it came from a Gateway write or a file edit. Later hot-reloadable writes do not erase a committed restart requirement while its application is pending.

The agents.create, agents.update, and agents.delete Gateway methods wait for runtime application before reporting success. A successful response lets clients immediately create sessions or read the updated agent roster. If the config was saved but could not be applied, including when reload is off, the method returns UNAVAILABLE with recovery guidance instead of reporting the agent change as ready. Inspect config.get before retrying a saved mutation.

If a busy state store temporarily refuses the reload's lifecycle lease, the Gateway keeps the change pending and retries automatically with increasing backoff, up to one final attempt after the five-second backoff. The previous runtime stays active until the change applies. Exhausted retries or a non-retryable admission failure return UNAVAILABLE to waiting config mutations; a later config observation can retry the saved change. Shutdown cancels retries and settles waiting mutations. Reload failures remain visible in the Gateway log.

If an automatic plugin reload cannot drain active work, the Gateway records the failure and keeps the last-good runtime. When the drain timed out on that plugin's admitted work, the Gateway retries the replacement automatically once the work finishes; no additional config edit is needed. Other drain failures wait for openclaw plugins reload <id> --wait or a revert of the pending plugin settings. Until then, later edits do not repeat the drain, and edits that still include the unapplied plugin settings stay pending; they cannot publish those settings through an unrelated hot update, and they apply together with the retry or recovery. While edits are pending, config.get reports an appliedConfigHash that differs from the saved revision, which the Control UI shows as unapplied config. openclaw plugins reload <id> --wait also lets you watch a timed-out replacement finish. A Gateway restart applies the saved config in full.

Direct file edits are treated as untrusted until they validate. The source's file adapter waits for editor temp-write/rename churn to settle, reads the final file, and rejects invalid external edits without rewriting openclaw.json. OpenClaw-owned config writes use the same schema gate before writing (see Strict validation for the clobber/rollback rules that apply to every write).

The adapter also watches included files and follows editor rename-replace writes. All reload consumers share the snapshot for each observation; a filesystem echo of a Gateway write keeps that write's application receipt and restart intent. A write publication also reconciles file edits already observed during its finalization, so it cannot discard a pending external change. Invalid edits leave the last good runtime active. Restart reads the same config files through the normal startup validation and recovery path; source revision numbers are local to the running Gateway.

If an external edit leaves the config missing or invalid during a Gateway write's final reread, a config.patch or config.apply waiting for runtime application returns UNAVAILABLE with the committed config details. It does not wait for another file event. Repair the file, run config.get, then reapply the intended config. The Gateway does not overwrite the external edit.

If you see config reload skipped (invalid config) or startup reports Invalid config, inspect the config, run openclaw config validate, then run openclaw doctor --fix for repair. See Gateway troubleshooting for the checklist.

A live change that selects a workspace with retired setup state is also rejected, with an openclaw doctor --fix hint. The Gateway keeps its last-good runtime. Gateway-managed writes, including config.set, reject the candidate before persistence; hand edits and writes from a separate CLI process can remain on disk even though the watcher refuses to activate them. Stop the Gateway and, if the write was rejected before persistence, save the intended workspace path while it is stopped. Then run openclaw doctor --fix and restart. Reload never migrates workspace state.

Reload modes

ModeBehavior
hybrid (default)Applies hot-reloadable settings. Automatically restarts when required.
offKeeps watching and validating config. Passive runtime changes wait for a manual restart; explicit plugin lifecycle actions still apply.
{
  gateway: {
    reload: { mode: "hybrid" },
  },
}

The earlier hot and restart modes are retired; openclaw doctor --fix maps both to hybrid. Reload debounce is no longer configurable and runs behind a built-in default.

What hot-applies vs what needs a restart

Reload planning classifies each changed path as one of three outcomes:

  • Gateway restart (restart): restart the Gateway process.
  • Hot reload (hot): apply the change while keeping the Gateway process running. This can include restarting the owning subsystem, such as a channel, cron, or heartbeat.
  • No reload action (none): update the runtime config snapshot without scheduling a reload action for that path. Consumers that read the current config can observe the new value on a later read.

In hybrid mode, Gateway restarts happen automatically when required. The longest matching config prefix determines the outcome. Rules supplied by a plugin apply only while that plugin is loaded; a path that matches no rule defaults to a Gateway restart.

By default, changing agents.defaults.mediaMaxMb restarts channel runtimes so their inherited attachment limits take effect together. Automatic reloads preserve manually stopped accounts; use an explicit channel start to resume those accounts.

Model runtime selection keeps your authored settings separate from catalog defaults. Hot reload and secrets reload preserve that distinction: catalog compatibility metadata does not become a custom request override that switches a native runtime back to OpenClaw. Changes to agents.defaults.models, agent model selection and fallbacks, and models.providers hot-apply without draining the Codex plugin. Changing Codex's own plugin settings still follows its plugin reload policy.

Agent sandbox tool allow/deny lists under agents.entries.<id>.tools.sandbox hot-apply without restarting plugin services. Workboard reads live session facts; File Transfer reloads only for workspace inputs.

If a service stop times out during config hot reload, that service remains owned and degraded while the Gateway keeps serving. Healthy services can finish their reloads. The warning names the plugin and service; plugin health includes its service failure. Once cleanup settles, retry openclaw plugins reload <id> to recover the affected plugin. A slow service cleanup does not schedule a Gateway restart.

Channel transport edits, such as channels.slack.streaming.mode, retain prepared session rows and model catalogs. Agent rosters, session policy, store topology, configured model references, and channel activation still invalidate their affected facts. When model or provider authentication inputs change, catalog requests wait for the replacement publication instead of reporting that startup is incomplete.

Changing session.store does not migrate conversations. Queued notifications bound to the previous physical store end with a recorded store-replaced outcome. Pending child-result delivery is suspended while the result and completed task remain available for explicit recovery; selecting the old store again does not automatically re-arm that delivery. Replacement and in-process restart that keep the same store preserve queued notification handoff.

CategoryFieldsGateway restart needed?
Channelschannels.*, web (WhatsApp)Depends on setting and loaded plugin
Agent & modelsagents, models, auth.order, auth.profiles, broadcast, worktreeRoot, worktreeAccelerationNo
Automationhooks, cron, agents.defaults.heartbeatNo (reloads the owning subsystem)
Sessions & messagessession, messagesNo
Tools & mediatools, skills, mcp except Apps listener settings, audio, talk, tts, memory.citations, attachments.ttlHoursNo
Plugin configplugins.entries.*, plugins.allow, plugins.deny, plugins.enabled, plugins.slots, plugins.load, legacy plugins.installsNo (reloads plugin runtime by default)
UI & miscui, logging, identity, bindings, surfacesNo
Approval & install policyapprovals.exec, approvals.plugin, security.installPolicy, security.audit.suppressionsNo (subsequent operations)
Diagnostics & ACPdiagnostics.flags, diagnostics.cacheTrace.enabled, acpNo (subsequent operations)
Updates & telemetryupdate.checkOnStart, update.channel, update.auto.enabled, telemetry.enabled, telemetry.consentedAtNo (next check)
Hosted URLsgateway.publicOrigin, mcp.apps.sandboxOriginNo (new URLs, hosted apps, and inherited browser-origin policy; disallowed browsers reconnect)
Gateway HTTP APIsgateway.http.endpoints, gateway.http.securityHeaders.strictTransportSecurityNo (next request)
Gateway tools & nodesgateway.tools, gateway.nodes.browser, gateway.nodes.pairing, gateway.nodes.commands, gateway.nodes.pluginTools.enabled, gateway.nodes.allowSkillsNo
Gateway client featuresgateway.cliAgents, selected gateway.controlUi settings belowNo
Gateway pushgateway.push.apns.relayNo (next push)
Gateway terminalgateway.terminalNo
Desktop and Cloud Workersdesktop.host, cloudWorkersNo (reconciles the owning service)
Gateway credentialsgateway.auth.token, gateway.auth.password, with the same effective auth modeNo (old shared-auth clients reconnect)
Gateway access policygateway.roles, gateway.trustedProxies, gateway.allowRealIpFallback, gateway.auth.allowTailscale, gateway.auth.identityScopes, gateway.auth.trustedProxyNo (clients reconnect with current authority)
Meeting capturetranscripts.enabled, transcripts.autoStartNo (reconciles capture writers)
Gateway auth limitsgateway.auth.rateLimitNo (retains limiter state)
Discovery visibilitydiscovery.mdns.modeNo (replaces discovery advertisements)
Browser defaultsbrowser.profiles, browser.defaultProfile, browser.headless, browser.executablePath, browser.attachOnly, browser.cdpUrl, browser.noSandbox, browser.extraArgs, browser.snapshotDefaults, browser.tabCleanup, browser.allowSystemProfileImportNo
Browser control policybrowser.enabled, browser.evaluateEnabled, browser.ssrfPolicy, browser.extensionRelay.allowLegacyAuthNo (replaces Browser control service)
Gateway serverOther gateway.* settings (port, bind, auth mode, tailscale, TLS)Yes
InfrastructureOther discovery and browser settings, MCP Apps listener settings, secrets.egressProxyYes

Channel plugins declare which settings restart their channel (reload.configPrefixes) and which need no reload action (reload.noopPrefixes). For example, with WhatsApp loaded, channels.whatsapp.enabled restarts the WhatsApp channel, while channels.whatsapp.replyToMode matches its broader no-action prefix.

Changes to channels.defaults, channels.modelByChannel, commands, accessGroups, tts, surfaces, acp.stream, and diagnostics.flags refresh loaded channel runtimes that capture those policies. Manually stopped accounts stay stopped, and the Gateway keeps running.

Inbound debounce settings apply at the next inbound admission without reconnecting supported channels. messages.ackReactionScope applies to subsequent turns without reconnecting Discord, Matrix, Signal, Slack, Telegram, or WhatsApp. Other channel plugins refresh unless they declare that they read the policy live. Per-channel and per-account overrides still take precedence; admitted turns retain their policy.

diagnostics.enabled updates diagnostic dispatch and heartbeat ownership live. With diagnostics-otel loaded, diagnostics.otel restarts only its exporter service, flushing the old generation before starting the new one. Externally preloaded OpenTelemetry providers retain their transport and shutdown ownership.

Audit collection (logging.audit.enabled, messages, and executionIdentity) applies to subsequent events and admissions. Disabling collection drains already accepted writes; enabling it does not reconstruct earlier events or add identity to runs already admitted without one. Existing retention policy is unchanged.

When Memory Core is selected, changes to models.providers reload its index service. Cached memory managers close before replacements use the new provider configuration, so correcting an embedding endpoint or credential does not require a Gateway restart. Existing indexes remain on disk.

Operation settings apply at their next use; they do not restart in-flight runs or recreate provisioned workers. Approval expiry changes affect newly issued grants. Attachment retention changes apply on the next cleanup sweep, including files already older than the new limit.

Update and telemetry settings apply at the next scheduled check. A pending automatic-update countdown rechecks enablement and channel selection before starting; an update already applying keeps its admitted target. Changing these settings does not force an update. Telemetry consent is read again before the next update-check request.

Internal-hook changes prepare a complete replacement before publishing it. A load failure keeps the previous handlers; events already running finish with their original handlers. Workspace changes reload directory hooks from the newly selected workspace. Reload does not replay gateway:startup.

Under gateway.controlUi, the enabled, environment, github, sessionObserver, embedSandbox, allowExternalEmbedUrls, experimental.customPlugins, and automaticallyFetchFavicons settings hot-apply. Reload open Control UI pages to pick up the environment label, CLI agent picker, embed preferences, and favicon display preference; the Gateway process keeps running. allowedOrigins and dangerouslyAllowHostHeaderOriginFallback also hot-apply: pending handshakes recheck the new policy, and browser connections it no longer allows close. Removing an admitted browser origin also revokes its accepted runs and delegated work, even after the connection has closed; removing an unrelated origin does not. Disabling the Control UI stops serving dashboard pages and assets and cancels pending asset preparation. Existing Gateway connections and agent runs continue. Re-enabling prepares missing dashboard assets in the background; requests return 503 until they are ready. Control UI serving paths still require a Gateway restart.

Custom plugin UI changes refresh plugin views in connected Control UI pages. Disabling it removes custom views and prevents new custom native UI loads; reload browser tabs to clear plugin JavaScript that already ran. Bundled plugin views and backend plugin operations remain available.

Host Desktop and Cloud Worker Desktop switches update connected desktop pickers without a Gateway restart. Host connection changes (managed, port, and passwordFile) retire existing observations and computer holds before the next use creates the replacement source. Disabling a source closes its desktop observations. Existing system VNC services and cloud workers remain running. Re-enabling restores the configured host source or existing desktop-capable workers. Cloud worker profile provisioning remains separate: settings.desktop affects newly provisioned workers.

Cloud Worker profile changes apply to newly provisioned workers. Running workers retain their admitted provisioning settings. Reserve counts and idle-suspension policy reconcile against the current config; changing a timeout cancels an outdated queued suspension. Repository profile defaults apply to future placement.

ACP enablement, dispatch, default agents, allowed agents, and backend policies apply to subsequent admissions and turns. Existing runtime handles survive unrelated config changes; backend failover retains its configured recovery behavior. Worktree acceleration applies to the next allocation or restoration.

Meeting capture changes reconcile through the transcript owner. Added sources start, removed or changed sources drain, and unchanged captures keep running. Title edits apply to future captures and preserve existing transcript titles. Disabling transcript storage stops capture writers without ending their meetings.

Role definitions, proxy trust, identity scopes, Tailscale authentication, and trusted-proxy policies apply live. Transport policy changes can require a new handshake without cancelling accepted runs. Proxy headers, OIDC mapping, device auto-approval, and proxy-address changes fence connections but preserve accepted work when the owner's grant is unchanged. This includes a requested initial turn after sessions.create commits its new session. Editing another login's identity scopes or reordering the same scopes keeps the connection and its accepted runs active. Changing the owner's identity-scope grant, removing that identity from the proxy allowlist, or disabling its authentication method revokes retained and delegated work, even if the grant is restored afterward. Shared-secret rotation also revokes work admitted with the old credential. Role restrictions remain enforced by each run's authority. Accepted policy writes can finish their response; subsequent requests must reauthenticate under the current transport policy. Changing authentication mode or listener topology still requires a Gateway restart.

Node command policy updates connected nodes immediately. Disabling node-published tools or skills withdraws them; re-enabling restores the last publication within the node's existing pairing approval. Reload never grants an unapproved command. Revoking a command cancels its active invocations and rejects later input and results. Revoking desktop streaming also closes its observer transports. Browser node routing applies to subsequent operations. Node pairing policy (gateway.nodes.pairing) also hot-applies: pending automatic approvals recheck the current policy before granting access, including after SSH checks. Existing paired devices remain paired. Terminal shell changes apply to newly opened terminals; active terminals keep their original shell. Detached-session timeout changes recalculate deadlines from each terminal's original disconnect time. Already-expired sessions close immediately; attached terminals keep running. Terminal enablement also hot-applies. Disabling terminals closes attached, detached, and conversation-owned sessions and cancels pending opens. Re-enabling allows fresh sessions; closed sessions do not return. Reload open Control UI pages to pick up the terminal's content security policy. An unrelated deferred restart does not delay a committed terminal enable or shell change. A pending restart can still keep earlier terminal or sandbox restrictions in force until that restart completes or its rejected changes are reverted.

Browser default-profile changes apply on the next request. Launch-setting changes replace affected managed browser processes when next used; externally attached browsers stay running. Browser enablement, evaluation, and SSRF policy changes replace only the Browser control service: pending operations cancel and owned Chrome processes close before the new policy applies. Attached and remote browser processes stay open while OpenClaw disconnects its control sessions. When enabled, Browser control starts again on demand; managed tabs from the retired process are not kept. Changing extension relay legacy authentication replaces the owned relay generation; externally managed relay daemons retain their own lifecycle and policy. Snapshot defaults apply to the next snapshot, and tab-cleanup settings apply on the next sweep.

TLS certificate renewal watches the files at the running Gateway's accepted certificate, key, and CA paths. Valid replacement material updates existing and future HTTPS listeners, discovery, and pairing fingerprints without interrupting connections. Incomplete or invalid replacements keep the previous material serving. Reload mode off pauses renewal; re-enabling checks changes made while paused. TLS configuration and path changes still require a Gateway restart. Remote certificate pins remain operator-controlled; see Gateway TLS.

Authentication rate-limit changes retain recorded failures, earned lockout deadlines, and pending loopback delays. New limits and loopback exemptions apply to subsequent attempts; tightening the attempt limit can lock a client based on its retained failures. Removing gateway.auth.rateLimit restores the defaults. Browser-origin and node-reapproval budgets remain nonexempt.

Discovery mode changes replace the current advertisements without interrupting Gateway connections. Switching from full to minimal removes extra TXT hints from LAN advertisements and any configured wide-area DNS-SD zone. off stops LAN advertisements while configured wide-area discovery remains enabled. The Bonjour plugin must already be enabled, and environment overrides still apply.

The Gateway accepts its configured secret whether the client sends it as a token or a password; gateway.auth.mode still decides which config value is the secret.

Local onboarding generates a Gateway secret by default (gateway.auth.mode: "token") without asking you to choose an auth mechanism. Existing password-mode configs are preserved. To choose your own password explicitly, use openclaw onboard --gateway-password <value> or --gateway-auth password. Remote onboarding asks for one Gateway secret and stores it as gateway.remote.token. See Onboard for storage choices and connecting without a shared secret.

Token and password rotation hot-applies only when the effective auth mode stays the same. Existing clients using the old shared credential must reconnect with the new credential; independently paired device-token clients remain connected. Browser device tokens derived from the old shared credential are revoked too. For SecretRef credentials, set gateway.auth.mode explicitly to make rotation eligible for hot reload. Auth-mode changes still restart the Gateway.

Changing gateway.reload or gateway.remote also does not trigger a restart.

Canvas enablement uses plugin hot reload. Current-protocol nodes whose hosted capabilities change reconnect to receive fresh capability URLs; other current-protocol nodes and operator connections stay open. Legacy nodes reconnect when hosted surface descriptors change so their protocol limits are recalculated. Pending node handshakes also recheck those capabilities before admission.

Ordinary runtime lookups use the cached plugin inventory and do not scan plugin files. In hybrid mode, edits under plugins.entries.<id> replace the affected instance by default and rerun registration with its new config. Unchanged plugin instances retain their registration snapshots. A plugin's narrower reload policy can retain an instance or require a restart.

Plugin install, update, enable, disable, uninstall, and metadata refresh apply through the running Gateway's plugin lifecycle without a Gateway restart. Explicit plugin actions also work when passive reload is off. Source or manifest edits need openclaw plugins reload <id>. Changing an agent workspace alone does not refresh plugin discovery; use an explicit metadata refresh. See Apply changes and inspect and Plugin metadata snapshots.

Agent requests waiting to start pause while plugin hot reload drains the old runtime. They continue with the replacement when it is ready, or with the previous runtime after a successful rollback. You do not need to resend these requests. Failed restoration or Gateway shutdown still reports a failure. If a replacement fails before activation, rollback restores the previous configured model context limits without waiting for model discovery.

If plugin replacement times out after stopping channels, the plugin lifecycle owner retries the admitted-work drain for up to 60 seconds before restoring the previous code and configuration with fresh registrations. It restarts channels after successful restoration and preserves manual stops. Unfinished writes keep their resource ownership; they are never discarded to force a replacement. If recovery reaches its deadline or cleanup fails, the operation ends as failed and releases channel reload pauses. Detailed /ready reports plugin-reload with the affected plugins and recovery instructions. Retry openclaw plugins reload <id> once the outstanding work settles, or restart the Gateway. See Plugin lifecycle for cleanup and ownership details.

During channel or plugin hot reload, Gateway-hosted channel webhook routes return 503 with Retry-After: 1 until replacement ingress registers. Senders must honor retry responses; this does not acknowledge delivery. Disabled or removed accounts, manual stops, and cancelled replacement lifetimes release those temporary routes. When replacement ingress reports ready, old paths it did not reclaim are removed.

Reload planning

When you edit a source file that is referenced through $include, OpenClaw plans the reload from the source-authored layout, not the flattened in-memory view. That keeps hot-reload decisions (hot-apply vs restart) predictable even when a single top-level section lives in its own included file such as plugins: { $include: "./plugins.json5" }. Reload planning fails closed if the source layout is ambiguous.