ops(docker): prune unused cache on deploys and nightly
CI / check (push) Failing after 23s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped

Add scripts/docker-prune.sh (build cache >72h capped at 4g, unreferenced images >7d, stopped containers >24h; never volumes), run it after every CI deploy and compose update, and schedule a nightly prune from the host-side jobs-worker. Tighten the deployment contract tests to assert the scoped-prune boundaries.
This commit is contained in:
openhands committed 2026-09-13 13:04:03 +02:00
1 parent fb68df3ba9
commit 47917bb63b
6 files changed
+102 -5

No files matched your search

+33
View File
@@ -0,0 +1,33 @@
#!/usr/bin/env bash
# Reclaim Docker's unused cache so host storage stays bounded.
#
# Safe scopes only, by design:
# - BuildKit cache older than 72h, hard-capped at 4 GB (Debian /pnpm store is
# shared across builds; everything newer than that speeds up rebuilds).
# - Images referenced by NO running/stopped container and older than 7 days
# (covers stale epicnext-cms sha tags, old mariadb/byparr pulls, etc.).
# - Containers stopped for more than 24h.
#
# Volumes are NEVER pruned here: mariadb-turbo-data is a database. This script
# is idempotent and exits 0 when Docker is unavailable.
set -Eeuo pipefail
DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
LOG_DIR="${LOG_DIR:-$DIR/logs}"
mkdir -p "$LOG_DIR"
LOG_FILE="$LOG_DIR/docker-prune.log"
now() { date '+%Y-%m-%d %H:%M:%S'; }
command -v docker >/dev/null 2>&1 || {
printf '[%s] docker CLI unavailable; nothing to prune\n' "$(now)" >>"$LOG_FILE"
exit 0
}
printf '\n[%s] === docker prune start ===\n' "$(now)" >>"$LOG_FILE"
docker system df >>"$LOG_FILE" 2>&1 || true
docker builder prune -af --filter "until=72h" --max-used-space=4g >>"$LOG_FILE" 2>&1 || true
docker image prune -af --filter "until=168h" >>"$LOG_FILE" 2>&1 || true
docker container prune -f --filter "until=24h" >>"$LOG_FILE" 2>&1 || true
printf '\n[%s] === docker prune complete ===\n' "$(now)" >>"$LOG_FILE"
docker system df >>"$LOG_FILE" 2>&1 || true