The host-side port mapping and seccomp compatibility-mode selections
were only used in-memory for docker run args and never written to
config.toml, so a re-run of the installer couldn't recover them as
form defaults (worse, the host port field silently defaulted to the
container's internal port). Add host_port and seccomp_unconfined to
[server] and decode them back via AppConfig.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds a StepRunUpdater step that starts app-dono-updater after the app
container comes up: a poll loop (docker pull, compare image IDs,
recreate on change) baked into the official docker:cli image via
`sh -c`, reusing the same docker run argv as the initial container
start so the two can't drift.
Not built on Watchtower: containrrr/watchtower was archived upstream
in Dec 2025 with no maintained successor recommended for production
use, so this avoids taking on that dependency.