v9.3.1
release-tag / release-image (push) Failing after 1m15s

This commit is contained in:
2026-08-31 22:17:18 +02:00
parent c6c25d26c3
commit 56170ccde9
19 changed files with 485 additions and 51 deletions
+8
View File
@@ -7,7 +7,15 @@ services:
APP_MODE: agent
AGENT_TOKEN: "replace-with-a-random-token-at-least-24-characters"
HTTP_TIMEOUT_SECONDS: "10"
# Optional: set HOST_ROOT=/host and mount /:/host:ro for identity checks.
HOST_ROOT: ""
ALLOW_HOST_USER_MANAGEMENT: "false"
ALLOW_HOST_PERMISSION_MANAGEMENT: "false"
volumes:
- ./agent-data:/data
- ./agent-stacks:/stacks
- /var/run/docker.sock:/var/run/docker.sock
# For read-only host UID/GID + bind ownership checks:
# - /:/host:ro
# For explicit admin host-user creation only: use /:/host:rw and set
# ALLOW_HOST_USER_MANAGEMENT=true.
@@ -0,0 +1,14 @@
# Optional read-only host identity inspection for a local/agent Dockwatch instance.
# Usage:
# docker compose -f compose.yml -f examples/compose-host-identity.override.yml up -d
#
# This lets Dockwatch map container UID/GID to host accounts and inspect ownership
# of bind-mount sources. It does NOT allow Dockwatch to create host users.
services:
dockwatch:
environment:
HOST_ROOT: /host
ALLOW_HOST_USER_MANAGEMENT: "false"
ALLOW_HOST_PERMISSION_MANAGEMENT: "false"
volumes:
- /:/host:ro
@@ -0,0 +1,10 @@
# High-trust opt-in for host bind-mount ownership/mode repair.
# Dockwatch can chown host files through /host, so use only on trusted machines.
services:
dockwatch:
environment:
HOST_ROOT: /host
ALLOW_HOST_USER_MANAGEMENT: "true"
ALLOW_HOST_PERMISSION_MANAGEMENT: "true"
volumes:
- /:/host:rw
@@ -0,0 +1,13 @@
# DANGEROUS / EXPLICIT OPT-IN:
# This gives Dockwatch write access to the host root so an administrator can create
# a local user/group matching a container's effective UID/GID. The Docker socket
# already grants broad host control, but this mount increases direct filesystem
# exposure. Use only on trusted hosts and keep ALLOW_HOST_USER_MANAGEMENT=false by default.
services:
dockwatch:
environment:
HOST_ROOT: /host
ALLOW_HOST_USER_MANAGEMENT: "true"
ALLOW_HOST_PERMISSION_MANAGEMENT: "false"
volumes:
- /:/host:rw
+8
View File
@@ -16,8 +16,16 @@ services:
CHECK_CONCURRENCY: "8"
CHECK_RETENTION_DAYS: "30"
HTTP_TIMEOUT_SECONDS: "10"
# Optional: set HOST_ROOT=/host and mount /:/host:ro for identity checks.
HOST_ROOT: ""
ALLOW_HOST_USER_MANAGEMENT: "false"
ALLOW_HOST_PERMISSION_MANAGEMENT: "false"
AUDIT_RETENTION_DAYS: "180"
volumes:
- ./master-data:/data
- ./master-stacks:/stacks
- /var/run/docker.sock:/var/run/docker.sock
# For read-only host UID/GID + bind ownership checks:
# - /:/host:ro
# For explicit admin host-user creation only: use /:/host:rw and set
# ALLOW_HOST_USER_MANAGEMENT=true.