First real end-to-end auto-update on a live install failed like this: Automatically updating trivy (a recovery snapshot is taken first) Snapshotting trivy before update… Pulling new image(s) for … Update of failed — rolling back… Could not roll back automatically The app name went empty after the snapshot. Cause: bash is dynamically scoped, so a callee assigning an undeclared variable writes the CALLER's local of that name — and a `while read app` loop leaves it EMPTY at EOF. webuiBackupAppStatus's dashboard generator runs at the end of every backup and did exactly that to updaterApplyApp's `app`. Nothing was damaged: the pull ran against an empty name, failed before touching the image, and the rollback was a no-op on a nonexistent app. Fixed both ends. The generator (and three gluetun loops with the same latent leak) now declare `local app`. updaterApplyApp/updaterRollbackApp hold the name in `_upd_app` so they no longer depend on every callee's hygiene, and updaterApplyAll stops leaking its own loop var. This is exactly the untested path the roadmap flagged: "apply/revert not yet exercised end-to-end on a live install with a pending update." Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
67 lines
2.7 KiB
Bash
67 lines
2.7 KiB
Bash
#!/bin/bash
|
|
|
|
# Force-recreates every installed app whose `CFG_<APP>_NETWORK=gluetun`
|
|
# so they re-resolve `network_mode: container:gluetun-service` against
|
|
# the *current* gluetun container ID.
|
|
#
|
|
# Background: Docker resolves `container:<name>` once at start time. If
|
|
# gluetun is later recreated (port-forward change, version bump, manual
|
|
# `docker compose up`), every routed app keeps the *old* container ID
|
|
# embedded in its NetworkMode and ends up in its own private netns —
|
|
# the host port mapping silently stops reaching anything because the
|
|
# app's HTTP server is no longer in gluetun's namespace.
|
|
#
|
|
# Call this whenever you've just touched gluetun in a way that recreates
|
|
# its container — see appNetworkRegisterPorts_gluetun and the gluetun
|
|
# install lifecycle for the two existing wiring sites.
|
|
appGluetunRecreateRouted()
|
|
{
|
|
if ! command -v sqlite3 >/dev/null 2>&1; then
|
|
return 0
|
|
fi
|
|
if [[ ! -f "$docker_dir/$db_file" ]]; then
|
|
return 0
|
|
fi
|
|
|
|
local installed_apps
|
|
installed_apps=$(runInstallOp sqlite3 "$docker_dir/$db_file" \
|
|
"SELECT name FROM apps WHERE status = 1 ORDER BY name;" 2>/dev/null)
|
|
|
|
if ! runFileOp docker ps --format '{{.Names}}' 2>/dev/null | grep -q '^gluetun-service$'; then
|
|
# Nothing to re-attach against; gluetun isn't running.
|
|
return 0
|
|
fi
|
|
|
|
local recreated=0
|
|
local app # local: bash is dynamically scoped, and a while-read loop
|
|
# leaves an undeclared name EMPTY in the CALLER's scope at EOF.
|
|
while IFS= read -r app; do
|
|
[[ -z "$app" || "$app" == "gluetun" ]] && continue
|
|
local app_config_file="${containers_dir}${app}/${app}.config"
|
|
[[ -f "$app_config_file" ]] || continue
|
|
|
|
local net
|
|
net=$(grep -E "^CFG_${app^^}_NETWORK=" "$app_config_file" 2>/dev/null \
|
|
| cut -d'=' -f2 | tr -d '"')
|
|
[[ "$net" != "gluetun" ]] && continue
|
|
|
|
local app_compose="${containers_dir}${app}/docker-compose.yml"
|
|
[[ -f "$app_compose" ]] || continue
|
|
|
|
# Skip apps with no running/created container — recreate would
|
|
# do nothing useful and we'd just emit noise.
|
|
if ! runFileOp docker ps -a --format '{{.Names}}' 2>/dev/null \
|
|
| grep -q "^${app}-service$"; then
|
|
continue
|
|
fi
|
|
|
|
isNotice "Re-attaching ${app} to gluetun's namespace (force-recreate)..."
|
|
dockerCommandRun "cd ${containers_dir}${app} && docker compose up -d --force-recreate ${app}-service" >/dev/null 2>&1 || true
|
|
((recreated++))
|
|
done <<< "$installed_apps"
|
|
|
|
if (( recreated > 0 )); then
|
|
isSuccessful "Re-attached ${recreated} gluetun-routed app(s) to the new gluetun namespace."
|
|
fi
|
|
}
|