-
Notifications
You must be signed in to change notification settings - Fork 64
Open
Description
Do not demand "Watchtower" in your default setup.
- Watchtower is a security issue, it requires
/var/run/docker.sockand so it has full capability to run as root on the host. As such it is a special case that should be checked and okay'd specifically by the end user. - You do seem to start watchtower in it's "Flagged containers only" mode, but you have omitted to name the container you want it to monitor.
- You also have not included any
scopearguments so it will kill other instances of itself.
You can (and perhaps should) suggest Watchtower, but putting it in the quick-start seems a supremely bad idea.
I do realise your pain with this, there is no good way of triggering automatic upgrades of docker images as part of docker, but Watchtower is not an image that should be run by a new docker user without warning.
Rondom, HeroCC, SpraxDev, hugalafutro, flotwig and 5 moreberezovskyi, emirkmo and Freekers
Metadata
Metadata
Assignees
Labels
No labels