Skip to content

NO, just no. watchtower is a bad tool to "force" on users. #76

@rdebath

Description

@rdebath

Do not demand "Watchtower" in your default setup.

  1. Watchtower is a security issue, it requires /var/run/docker.sock and so it has full capability to run as root on the host. As such it is a special case that should be checked and okay'd specifically by the end user.
  2. You do seem to start watchtower in it's "Flagged containers only" mode, but you have omitted to name the container you want it to monitor.
  3. You also have not included any scope arguments so it will kill other instances of itself.

You can (and perhaps should) suggest Watchtower, but putting it in the quick-start seems a supremely bad idea.

I do realise your pain with this, there is no good way of triggering automatic upgrades of docker images as part of docker, but Watchtower is not an image that should be run by a new docker user without warning.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions