feat: auto-update app-dono-cliente when a new image is pushed to :latest

Adds a StepRunUpdater step that starts app-dono-updater after the app
container comes up: a poll loop (docker pull, compare image IDs,
recreate on change) baked into the official docker:cli image via
`sh -c`, reusing the same docker run argv as the initial container
start so the two can't drift.

Not built on Watchtower: containrrr/watchtower was archived upstream
in Dec 2025 with no maintained successor recommended for production
use, so this avoids taking on that dependency.
This commit is contained in:
2026-08-26 12:30:44 -03:00
parent ef126eaf61
commit a05b98fdf5
8 changed files with 244 additions and 18 deletions
+5 -1
View File
@@ -75,7 +75,9 @@ Makefile Multi-arch build + S3 publish.
5. `StepReview` — shows all collected config; Enter confirms.
6. `StepGenerateFile` — writes `config.toml` (validates numeric fields first).
7. `StepRunDocker` — runs `app-dono-cliente` container.
8. `StepDone`.
8. `StepRunUpdater` — runs `app-dono-updater`, which auto-updates `app-dono-cliente`
whenever a new image is pushed to `:latest`.
9. `StepDone`.
### Navigation & error handling
@@ -95,6 +97,7 @@ In [update.go](internal/tui/update.go):
- `imageName = hub.davinti.com.br:443/app-dono/app-cliente:latest`
- `wireguardImageName = hub.davinti.com.br:443/davinti-vproxy:latest`
- `updaterImageName = docker:cli`
- `configPath = config.toml`, `wireguardConfigPath = envs`
In [docker.go](internal/tui/docker.go): `networkName = app-dono_app` (all containers
@@ -115,6 +118,7 @@ Both are gitignored.
| ------------------ | -------------------- | -------------------------------------------------------- |
| `app-dono-cliente` | app-cliente | `<host port>:8080`, mounts config.toml + cert dir, `--restart unless-stopped`, runs as host uid:gid. |
| `vproxy` | davinti-vproxy | `--cap-add=NET_ADMIN`, `/dev/net/tun`, `--env-file envs`, only without public IP. |
| `app-dono-updater` | docker:cli | Not a third-party updater — a poll loop (`sh -c`) baked into the official `docker:cli` image, since Watchtower was archived upstream in Dec 2025 with no maintained successor recommended for production. Every `updaterPollIntervalSeconds` (300s) it `docker pull`s `app-dono-cliente`'s image, compares image IDs, and if changed, stops/removes/recreates the container using the exact same `docker run` argv as the original start (`appClienteRunArgs` in `docker.go`, shared by both call sites so they can't drift). Mounts `/var/run/docker.sock` and the host's `~/.docker/config.json` (written by the earlier `docker login`) for private-registry auth. Not on `app-dono_app` — only talks to the Docker daemon. |
`seccomp=unconfined` is added to either container when the "Modo Compatibilidade"
(`seccomp_unconfined`) select is `"Sim"` — for old machines.