Re-fetches every --ip-blocklist source every N seconds and atomically swaps in the new contents, so a long-lived server or MCP process tracks an evolving threat feed without a restart. The value must be at least 1.
Each refresh is best-effort per source: a source that fetches and parses cleanly replaces its own entries, while one that fails keeps its previous entries and logs an error. The process keeps serving on its prior blocklist.
This is an Enterprise-tier flag.