Files
composes/diun/compose.yml
T
tiennm99 24cefe80a2 feat(diun): add diun template reading the Docker API through a proxy
Diun needs the Docker API to enumerate containers and inspect each one's
image. Mounting the socket into it directly is host-root-equivalent, and :ro on
a socket mount is cosmetic, so the socket goes into a docker-socket-proxy
sidecar and Diun reaches it at tcp://dockerproxy:2375. POST is revoked there,
so container create and exec return 403.

CONTAINERS and IMAGES are both required: with CONTAINERS alone the provider
loads and enumerates containers, then every ImageInspect returns 403 and
nothing is analysed. Verified against a live watch cycle — 25 images analysed,
no errors.

Pin crazymax/diun:4.33 rather than :latest, since this is the service whose job
is to talk to the daemon.
2026-09-19 17:18:31 +07:00

39 lines
1.2 KiB
YAML

# Required env vars (set in Coolify/Dokploy, or a sibling .env):
# DIUN_NOTIF_TELEGRAM_TOKEN, DIUN_NOTIF_TELEGRAM_CHATIDS
services:
diun:
image: crazymax/diun:4.33
command: serve
environment:
DIUN_PROVIDERS_DOCKER: "true"
DIUN_PROVIDERS_DOCKER_ENDPOINT: tcp://dockerproxy:2375
DIUN_PROVIDERS_DOCKER_WATCHBYDEFAULT: "${DIUN_PROVIDERS_DOCKER_WATCHBYDEFAULT:-true}"
DIUN_NOTIF_TELEGRAM_TOKEN: ${DIUN_NOTIF_TELEGRAM_TOKEN:?required}
DIUN_NOTIF_TELEGRAM_CHATIDS: ${DIUN_NOTIF_TELEGRAM_CHATIDS:?required}
DIUN_DB_PATH: /data/diun.db
DIUN_WATCH_SCHEDULE: "${DIUN_WATCH_SCHEDULE:-0 */6 * * *}"
DIUN_WATCH_WORKERS: "${DIUN_WATCH_WORKERS:-10}"
DIUN_WATCH_JITTER: "${DIUN_WATCH_JITTER:-30s}"
TZ: "${TZ:-UTC}"
LOG_LEVEL: "${LOG_LEVEL:-info}"
LOG_JSON: "${LOG_JSON:-false}"
volumes:
- diun-data:/data
depends_on:
- dockerproxy
# Read-only slice of the Docker API. POST is revoked by default in this image.
dockerproxy:
image: tecnativa/docker-socket-proxy:v0.5.0
environment:
CONTAINERS: 1
IMAGES: 1
security_opt:
- no-new-privileges:true
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
volumes:
diun-data: