From b626c5b70da4e6867f6eff93cec88c0861f18252 Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Sun, 20 Sep 2026 12:50:04 +0700 Subject: [PATCH] chore(diun): track moving image tags instead of exact pins Diun follows the upstream major tag 4; the socket proxy follows latest, since that project publishes no moving major tag. --- diun/README.md | 19 +++++++++++++++---- diun/compose.yml | 4 ++-- 2 files changed, 17 insertions(+), 6 deletions(-) diff --git a/diun/README.md b/diun/README.md index c69844b..9cddcc3 100644 --- a/diun/README.md +++ b/diun/README.md @@ -56,7 +56,18 @@ notifications for everything currently running. ## Version pinning -`crazymax/diun:4.33` rather than `:latest`. Diun holds Docker API access, so an -unreviewed image change is the highest-leverage supply-chain step on the host; -the proxy bounds what a bad image could do, and the pin means an image only -changes when this file does. +`crazymax/diun:4` — the moving major tag, so patch and minor releases arrive on +the next pull without an edit here, while a breaking `5.x` never does. The +upstream project publishes `4` alongside every `4.x.y`, so the tag always +resolves to the newest release of that line. + +`tecnativa/docker-socket-proxy:latest`. That project only publishes exact tags +(`v0.5.0`, `v0.4.2`, …) for its current scheme — the bare `0` and `0.3` tags +are stale leftovers from an older one — so there is no moving major tag to +follow and `latest` is the closest equivalent. + +Moving tags mean an image can change under a redeploy without this file +changing. That is the accepted trade-off: Diun is the one service here holding +Docker API access, and the proxy is what bounds the damage a bad image could do +— `POST` is revoked, so no image pulled through either tag can create a +privileged container. diff --git a/diun/compose.yml b/diun/compose.yml index f4a4584..4759c13 100644 --- a/diun/compose.yml +++ b/diun/compose.yml @@ -3,7 +3,7 @@ services: diun: - image: crazymax/diun:4.33 + image: crazymax/diun:4 command: serve environment: DIUN_PROVIDERS_DOCKER: "true" @@ -25,7 +25,7 @@ services: # Read-only slice of the Docker API. POST is revoked by default in this image. dockerproxy: - image: tecnativa/docker-socket-proxy:v0.5.0 + image: tecnativa/docker-socket-proxy:latest environment: CONTAINERS: 1 IMAGES: 1