Add scripts/docker-prune.sh (build cache >72h capped at 4g, unreferenced images >7d, stopped containers >24h; never volumes), run it after every CI deploy and compose update, and schedule a nightly prune from the host-side jobs-worker. Tighten the deployment contract tests to assert the scoped-prune boundaries.
33 lines
1.4 KiB
Bash
33 lines
1.4 KiB
Bash
#!/usr/bin/env bash
|
|
# Reclaim Docker's unused cache so host storage stays bounded.
|
|
#
|
|
# Safe scopes only, by design:
|
|
# - BuildKit cache older than 72h, hard-capped at 4 GB (Debian /pnpm store is
|
|
# shared across builds; everything newer than that speeds up rebuilds).
|
|
# - Images referenced by NO running/stopped container and older than 7 days
|
|
# (covers stale epicnext-cms sha tags, old mariadb/byparr pulls, etc.).
|
|
# - Containers stopped for more than 24h.
|
|
#
|
|
# Volumes are NEVER pruned here: mariadb-turbo-data is a database. This script
|
|
# is idempotent and exits 0 when Docker is unavailable.
|
|
set -Eeuo pipefail
|
|
DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
|
LOG_DIR="${LOG_DIR:-$DIR/logs}"
|
|
mkdir -p "$LOG_DIR"
|
|
LOG_FILE="$LOG_DIR/docker-prune.log"
|
|
now() { date '+%Y-%m-%d %H:%M:%S'; }
|
|
|
|
command -v docker >/dev/null 2>&1 || {
|
|
printf '[%s] docker CLI unavailable; nothing to prune\n' "$(now)" >>"$LOG_FILE"
|
|
exit 0
|
|
}
|
|
|
|
printf '\n[%s] === docker prune start ===\n' "$(now)" >>"$LOG_FILE"
|
|
docker system df >>"$LOG_FILE" 2>&1 || true
|
|
|
|
docker builder prune -af --filter "until=72h" --max-used-space=4g >>"$LOG_FILE" 2>&1 || true
|
|
docker image prune -af --filter "until=168h" >>"$LOG_FILE" 2>&1 || true
|
|
docker container prune -f --filter "until=24h" >>"$LOG_FILE" 2>&1 || true
|
|
|
|
printf '\n[%s] === docker prune complete ===\n' "$(now)" >>"$LOG_FILE"
|
|
docker system df >>"$LOG_FILE" 2>&1 || true |