feat: auto-update app-dono-cliente when a new image is pushed to :latest
Adds a StepRunUpdater step that starts app-dono-updater after the app container comes up: a poll loop (docker pull, compare image IDs, recreate on change) baked into the official docker:cli image via `sh -c`, reusing the same docker run argv as the initial container start so the two can't drift. Not built on Watchtower: containrrr/watchtower was archived upstream in Dec 2025 with no maintained successor recommended for production use, so this avoids taking on that dependency.
This commit is contained in:
@@ -114,3 +114,13 @@ func RunWireguardContainer(path string, cv ConfigValues) tea.Cmd {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func RunUpdaterContainer(appImage, appContainerName, configPath, configDestinationPath string, cv ConfigValues) tea.Cmd {
|
||||
return func() tea.Msg {
|
||||
err := RunUpdaterDockerContainer(appImage, appContainerName, configPath, configDestinationPath, cv)
|
||||
|
||||
return DockerRunMsg{
|
||||
Err: err,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+112
-9
@@ -2,6 +2,7 @@ package tui
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"os/exec"
|
||||
"os/user"
|
||||
"path/filepath"
|
||||
@@ -106,21 +107,18 @@ func RunWireguardDockerContainer(envFilePath string, cv ConfigValues) error {
|
||||
return verifyContainerRunning(containerID)
|
||||
}
|
||||
|
||||
func RunAppClienteContainer(image, containerName, configPath, configDestinationPath string, cv ConfigValues) error {
|
||||
removeExistingContainer(containerName)
|
||||
|
||||
if err := EnsureNetwork(networkName); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// appClienteRunArgs builds the `docker run` argv for the app-dono-cliente container.
|
||||
// Shared by RunAppClienteContainer (initial start) and RunUpdaterDockerContainer (which
|
||||
// re-embeds the same argv in its recreate script), so the two never drift apart.
|
||||
func appClienteRunArgs(image, containerName, configPath, configDestinationPath string, cv ConfigValues) ([]string, error) {
|
||||
absPath, err := filepath.Abs(configPath)
|
||||
if err != nil {
|
||||
return fmt.Errorf("erro ao resolver caminho absoluto: %w", err)
|
||||
return nil, fmt.Errorf("erro ao resolver caminho absoluto: %w", err)
|
||||
}
|
||||
|
||||
currentUser, err := user.Current()
|
||||
if err != nil {
|
||||
return err
|
||||
return nil, err
|
||||
}
|
||||
uidGid := fmt.Sprintf("%s:%s", currentUser.Uid, currentUser.Gid)
|
||||
|
||||
@@ -138,6 +136,111 @@ func RunAppClienteContainer(image, containerName, configPath, configDestinationP
|
||||
args = append(args, "--security-opt", "seccomp=unconfined")
|
||||
}
|
||||
args = append(args, image)
|
||||
return args, nil
|
||||
}
|
||||
|
||||
func RunAppClienteContainer(image, containerName, configPath, configDestinationPath string, cv ConfigValues) error {
|
||||
removeExistingContainer(containerName)
|
||||
|
||||
if err := EnsureNetwork(networkName); err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
args, err := appClienteRunArgs(image, containerName, configPath, configDestinationPath, cv)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
cmd := exec.Command("docker", args...)
|
||||
|
||||
out, err := cmd.CombinedOutput()
|
||||
if err != nil {
|
||||
return fmt.Errorf("docker run falhou: %w\noutput: %s", err, string(out))
|
||||
}
|
||||
|
||||
time.Sleep(2 * time.Second)
|
||||
containerID := strings.TrimSpace(string(out))
|
||||
return verifyContainerRunning(containerID)
|
||||
}
|
||||
|
||||
// shellQuote POSIX single-quotes s for safe embedding in the updater's poll script:
|
||||
// wrap in '...', escaping any embedded ' as '\''. Needed because cv fields (e.g.
|
||||
// cert_dir_path) are operator-entered and end up inside a shell script, not a plain
|
||||
// argv slot.
|
||||
func shellQuote(s string) string {
|
||||
return "'" + strings.ReplaceAll(s, "'", `'\''`) + "'"
|
||||
}
|
||||
|
||||
func shellQuoteArgs(args []string) string {
|
||||
quoted := make([]string, len(args))
|
||||
for i, a := range args {
|
||||
quoted[i] = shellQuote(a)
|
||||
}
|
||||
return strings.Join(quoted, " ")
|
||||
}
|
||||
|
||||
// updaterPollIntervalSeconds is how often the updater checks the registry for a new
|
||||
// app-cliente image.
|
||||
const updaterPollIntervalSeconds = 300
|
||||
|
||||
// RunUpdaterDockerContainer starts a tiny self-contained auto-updater for the
|
||||
// app-dono-cliente container: no third-party updater project, just the official
|
||||
// `docker:cli` image running a poll loop (docker pull, compare image IDs, recreate on
|
||||
// change) written in Go and handed to it via `sh -c`. This exists because Watchtower
|
||||
// (the previous approach) was archived upstream with no maintained drop-in successor
|
||||
// recommended for production use — see StepRunUpdater in update.go.
|
||||
//
|
||||
// It mounts the docker socket (to pull/recreate) and the host's docker config.json
|
||||
// (written by the StepDockerLogin `docker login`) so `docker pull` can authenticate
|
||||
// against the private registry.
|
||||
func RunUpdaterDockerContainer(appImage, appContainerName, configPath, configDestinationPath string, cv ConfigValues) error {
|
||||
updaterName := "app-dono-updater"
|
||||
|
||||
removeExistingContainer(updaterName)
|
||||
|
||||
if out, err := PullImage(updaterImageName); err != nil {
|
||||
return fmt.Errorf("erro ao baixar imagem do atualizador: %w\noutput: %s", err, out)
|
||||
}
|
||||
|
||||
home, err := os.UserHomeDir()
|
||||
if err != nil {
|
||||
return fmt.Errorf("erro ao localizar diretório home: %w", err)
|
||||
}
|
||||
dockerConfigPath := filepath.Join(home, ".docker", "config.json")
|
||||
|
||||
recreateArgs, err := appClienteRunArgs(appImage, appContainerName, configPath, configDestinationPath, cv)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
recreateCmd := "docker " + shellQuoteArgs(recreateArgs)
|
||||
|
||||
script := fmt.Sprintf(`set -e
|
||||
IMAGE=%s
|
||||
NAME=%s
|
||||
while true; do
|
||||
docker pull "$IMAGE" >/dev/null 2>&1 || true
|
||||
CURRENT=$(docker inspect --format '{{.Image}}' "$NAME" 2>/dev/null || true)
|
||||
LATEST=$(docker inspect --format '{{.Id}}' "$IMAGE" 2>/dev/null || true)
|
||||
if [ -n "$LATEST" ] && [ "$CURRENT" != "$LATEST" ]; then
|
||||
docker stop "$NAME" >/dev/null 2>&1 || true
|
||||
docker rm "$NAME" >/dev/null 2>&1 || true
|
||||
%s
|
||||
fi
|
||||
sleep %d
|
||||
done
|
||||
`, shellQuote(appImage), shellQuote(appContainerName), recreateCmd, updaterPollIntervalSeconds)
|
||||
|
||||
args := []string{
|
||||
"run", "-d",
|
||||
"--name", updaterName,
|
||||
"--restart", "unless-stopped",
|
||||
"-v", "/var/run/docker.sock:/var/run/docker.sock",
|
||||
"-v", fmt.Sprintf("%s:/config.json", dockerConfigPath),
|
||||
"--log-opt", "max-size=5m",
|
||||
"--log-opt", "max-file=1",
|
||||
"--entrypoint", "sh",
|
||||
updaterImageName,
|
||||
"-c", script,
|
||||
}
|
||||
cmd := exec.Command("docker", args...)
|
||||
|
||||
out, err := cmd.CombinedOutput()
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
package tui
|
||||
|
||||
import (
|
||||
"os/exec"
|
||||
"reflect"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// TestShellQuoteArgsRoundTrip guards the updater's poll-script generation: cv fields
|
||||
// (e.g. cert_dir_path) are operator-entered and get embedded into a shell script run
|
||||
// inside the updater container. If shellQuote/shellQuoteArgs mis-escapes a value, that's
|
||||
// a command-injection bug, not just a cosmetic one. This feeds tricky values through a
|
||||
// real `sh` and checks they come back out exactly as they went in.
|
||||
func TestShellQuoteArgsRoundTrip(t *testing.T) {
|
||||
if _, err := exec.LookPath("sh"); err != nil {
|
||||
t.Skip("sh not available")
|
||||
}
|
||||
|
||||
cases := [][]string{
|
||||
{"simple"},
|
||||
{"has space"},
|
||||
{"it's got a quote"},
|
||||
{"$(echo injected)"},
|
||||
{"a;b|c&d"},
|
||||
{"back`tick`"},
|
||||
{"multi", "arg space", "o'clock", "$HOME", "'"},
|
||||
}
|
||||
|
||||
for _, args := range cases {
|
||||
script := "printf '%s\\n' " + shellQuoteArgs(args)
|
||||
out, err := exec.Command("sh", "-c", script).Output()
|
||||
if err != nil {
|
||||
t.Fatalf("sh failed for %v: %v", args, err)
|
||||
}
|
||||
got := strings.Split(strings.TrimRight(string(out), "\n"), "\n")
|
||||
if !reflect.DeepEqual(got, args) {
|
||||
t.Errorf("round trip mismatch for %v: got %v", args, got)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -30,6 +30,7 @@ const (
|
||||
// Finalizing
|
||||
StepGenerateFile
|
||||
StepRunDocker
|
||||
StepRunUpdater
|
||||
StepDone
|
||||
)
|
||||
|
||||
|
||||
@@ -11,6 +11,7 @@ import (
|
||||
const (
|
||||
imageName = "hub.davinti.com.br:443/app-dono/app-cliente:latest"
|
||||
wireguardImageName = "hub.davinti.com.br:443/davinti-vproxy:latest"
|
||||
updaterImageName = "docker:cli"
|
||||
configPath = "config.toml"
|
||||
wireguardConfigPath = "envs"
|
||||
)
|
||||
@@ -138,6 +139,8 @@ func (m Model) Update(msg tea.Msg) (tea.Model, tea.Cmd) {
|
||||
return m.updateGenerateFile(msg)
|
||||
case StepRunDocker:
|
||||
return m.updateRunDocker(msg)
|
||||
case StepRunUpdater:
|
||||
return m.updateRunUpdater(msg)
|
||||
case StepDone:
|
||||
return m, tea.Quit
|
||||
}
|
||||
@@ -396,6 +399,49 @@ func (m Model) updateRunDocker(msg tea.Msg) (tea.Model, tea.Cmd) {
|
||||
default:
|
||||
return m, tea.Quit
|
||||
}
|
||||
} else if m.finishedDockerRun && m.dockerRunError == nil {
|
||||
m.currentStep = StepRunUpdater
|
||||
|
||||
m.finishedDockerRun = false
|
||||
m.dockerRunError = nil
|
||||
|
||||
return m, RunUpdaterContainer(
|
||||
imageName,
|
||||
"app-dono-cliente",
|
||||
configPath,
|
||||
fmt.Sprintf("/app/%s", configPath),
|
||||
m.configValues,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
return m, nil
|
||||
}
|
||||
|
||||
// updateRunUpdater starts the auto-update agent that watches the app-dono-cliente
|
||||
// container and pulls/recreates it whenever a new image is pushed to :latest.
|
||||
func (m Model) updateRunUpdater(msg tea.Msg) (tea.Model, tea.Cmd) {
|
||||
switch msg := msg.(type) {
|
||||
case DockerRunMsg:
|
||||
m.finishedDockerRun = true
|
||||
m.dockerRunError = msg.Err
|
||||
|
||||
case tea.KeyPressMsg:
|
||||
if m.finishedDockerRun && m.dockerRunError != nil {
|
||||
switch msg.String() {
|
||||
case "r":
|
||||
m.finishedDockerRun = false
|
||||
m.dockerRunError = nil
|
||||
return m, RunUpdaterContainer(
|
||||
imageName,
|
||||
"app-dono-cliente",
|
||||
configPath,
|
||||
fmt.Sprintf("/app/%s", configPath),
|
||||
m.configValues,
|
||||
)
|
||||
default:
|
||||
return m, tea.Quit
|
||||
}
|
||||
} else if m.finishedDockerRun && m.dockerRunError == nil {
|
||||
m.currentStep = StepDone
|
||||
}
|
||||
|
||||
@@ -107,6 +107,11 @@ func (m Model) View() tea.View {
|
||||
if m.finishedDockerRun && m.dockerRunError != nil {
|
||||
helpMsg = retryMsg
|
||||
}
|
||||
case StepRunUpdater:
|
||||
body = m.viewDockerRun()
|
||||
if m.finishedDockerRun && m.dockerRunError != nil {
|
||||
helpMsg = retryMsg
|
||||
}
|
||||
case StepDone:
|
||||
body = m.viewDoneMessage()
|
||||
helpMsg = anyKeyOutMsg
|
||||
|
||||
Reference in New Issue
Block a user