Kubernetes ConfigMap Changed but Pods Don't See It

Volume-mounted ConfigMaps update (slowly, and only for some subPath cases); envFrom/Env vars NEVER update. Know the mechanism your app uses and the answer changes.

What you'll see

Root causes

Environment-variable-injected ConfigMaps are immutable per-pod

envFrom/env values are captured at container start — changing the ConfigMap does nothing for running pods. Restart required, by design.

Volume-mounted config + propagation delay or subPath

Volume-mounted ConfigMaps sync eventually (up to ~a minute + kubelet sync period), BUT subPath mounts never update. Apps that read the file once at startup also never see changes.

Fix it

  1. Confirm what's actually mounted in the pod now
    kubectl exec <pod> -- cat /etc/config/app.conf | head -5 ; kubectl get configmap <cm> -o yaml | head -10
  2. Roll the pods to pick up new config (env-var pattern)
    kubectl rollout restart deployment <app>   # the honest fix for envFrom
  3. For mounted files: verify mount type (no subPath) and app re-reads
    kubectl get pod <pod> -o jsonpath='{.spec.volumes[*].configMap}' | python3 -m json.tool
  4. Make updates automatic: checksum annotation triggers rollouts
    # spec.template.metadata.annotations: configmap/checksum: {{ include (print .Values.configMap) . | sha256sum }} — helm/argo pattern: change config → new pod hash → rollout

Field note

Immutable ConfigMaps (immutable: true) exist to stop the sync cost entirely — good for config that never changes in place. The checksum annotation is the standard helm pattern; with plain manifests, pair ConfigMap bumps with rollout restart in your deploy pipeline.

Common questions

Doesn't Kubernetes hot-reload ConfigMaps?

Only volume-mounted ones, eventually, and not through subPath — never env-var injections. If your app reads config once at boot, even a synced file won't help: restart on change regardless.

What's the clean way to deploy config changes?

Treat config as part of the release: bump the ConfigMap and rollout restart in one step (or the checksum-annotation pattern so the rollout triggers automatically). Consistent and observable.

Ship it right the first time

Kustomize base with probes, PDBs, and zero-downtime rollouts already wired.

Kubernetes Production Blueprints — $27 →

One-time. Yours to modify. Instant download from the NinjaOps template store.