#!/usr/bin/env bash # Reclaim Docker's unused cache so host storage stays bounded. # # Modes: # (default) — post-deploy cleanup (safe, fast): # - ALL unreferenced build cache (new build will re-populate what it needs). # - ALL unreferenced images older than 1h (keeps current image + very recent). # - ALL stopped containers older than 1h. # --force — emergency mode ("never let the disk max out"): drops everything # with no age windows: # - ALL unreferenced build cache, # - ALL unreferenced images (no age grace), # - ALL stopped containers. # # Volumes are NEVER pruned in either mode: mariadb-turbo-data is a database. # Idempotent; exits 0 when Docker is unavailable. set -Eeuo pipefail DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" LOG_DIR="${LOG_DIR:-$DIR/logs}" mkdir -p "$LOG_DIR" LOG_FILE="$LOG_DIR/docker-prune.log" now() { date '+%Y-%m-%d %H:%M:%S'; } FORCE=0 if [[ "${1:-}" == "--force" ]]; then FORCE=1 fi command -v docker >/dev/null 2>&1 || { printf '[%s] docker CLI unavailable; nothing to prune\n' "$(now)" >>"$LOG_FILE" exit 0 } printf '\n[%s] === docker prune start%s ===\n' "$(now)" "$( (( FORCE )) && printf ' (FORCE)' )" >>"$LOG_FILE" docker system df >>"$LOG_FILE" 2>&1 || true if (( FORCE )); then docker builder prune -af >>"$LOG_FILE" 2>&1 || true docker image prune -af >>"$LOG_FILE" 2>&1 || true docker container prune -f >>"$LOG_FILE" 2>&1 || true else docker builder prune -af >>"$LOG_FILE" 2>&1 || true docker image prune -af --filter "until=1h" >>"$LOG_FILE" 2>&1 || true docker container prune -f --filter "until=1h" >>"$LOG_FILE" 2>&1 || true fi printf '\n[%s] === docker prune complete%s ===\n' "$(now)" "$( (( FORCE )) && printf ' (FORCE)' )" >>"$LOG_FILE" docker system df >>"$LOG_FILE" 2>&1 || true