Bulwark is a Docker container update management tool designed for safety, transparency, and control.
2.1K
Safe, policy-driven Docker container updater with digest-based change detection and rollback capability.
Bulwark is a Docker container update management tool designed for safety, transparency, and control. Unlike aggressive auto-updaters, Bulwark provides:
docker compose for proper project handlingcp .env.example .env
# Edit .env as needed (do not commit it)
docker compose pull bulwark
docker compose up -d bulwark
Visit http://localhost:8085 to access the Web Console (default compose port).
Use a manual/externally-triggered update flow for the Bulwark service:
docker compose pull bulwark
docker compose up -d bulwark
By default, Bulwark now skips self-updates during apply to avoid recreating the process that is currently orchestrating updates.
Set BULWARK_ALLOW_SELF_UPDATE=true only if you intentionally want Bulwark to attempt self-updates.
docker build -t bulwark:dev .
docker run --rm -p 8080:8080 \
-v /var/run/docker.sock:/var/run/docker.sock \
-v /docker_data:/docker_data:ro \
-e BULWARK_UI_ENABLED=true \
-e BULWARK_UI_READONLY=true \
bulwark:dev
Visit http://localhost:8080 to access the Web Console.
go install github.com/itsmrshow/bulwark/cmd/bulwark@latest
Replace github.com/itsmrshow/bulwark with your actual repo path if you fork.
Or build manually:
git clone https://github.com/itsmrshow/bulwark.git
cd bulwark
make build
# Discover managed targets
bulwark discover
# Check for available updates
bulwark check
# Plan updates (dry-run)
bulwark plan
# Apply updates
bulwark apply
# Run the Web Console (API + UI)
bulwark serve
Bulwark includes a production-ready Web Console that is read-only by default. Write actions (apply/rollback) must be explicitly enabled and are protected by a bearer token.
# Terminal 1: run the API/UI server
export BULWARK_UI_ENABLED=true
export BULWARK_UI_READONLY=true
bulwark serve
# Terminal 2: run the frontend dev server
cd web
npm install
npm run dev
Open http://localhost:5173 for the Vite dev server (it proxies /api to http://localhost:8080).
export BULWARK_UI_READONLY=false
export BULWARK_WEB_TOKEN="your-strong-token"
Then add Authorization: Bearer <token> for write requests, or enter the token in the UI header.
Configure notification webhooks in Settings inside the Web Console. You can:
Notifications are only sent when updates are available.
Environment overrides:
DISCORD_WEBHOOK_URL / SLACK_WEBHOOK_URL will preconfigure webhooks and lock them in the UI.BULWARK_NOTIFY_ON_FIND enables immediate notifications without using the UI.BULWARK_NOTIFY_DIGEST enables digest notifications without using the UI.BULWARK_NOTIFY_CHECK_CRON / BULWARK_NOTIFY_DIGEST_CRON override the notification schedules./data/bulwark.json by default (configure with BULWARK_DATA_DIR or BULWARK_CONFIG_PATH).Enable Bulwark management on your containers using labels:
services:
nginx:
image: nginx:latest
labels:
- bulwark.enabled=true
- bulwark.policy=safe
- bulwark.tier=stateless
- bulwark.probe.type=http
- bulwark.probe.url=http://localhost:80
- bulwark.probe.expect_status=200
services:
postgres:
image: postgres:15
labels:
- bulwark.enabled=true
- bulwark.policy=notify # Only notify, never auto-update
- bulwark.tier=stateful
docker run -d \
--name myapp \
--label bulwark.enabled=true \
--label bulwark.policy=safe \
--label bulwark.definition=compose:/docker_data/myapp/docker-compose.yml#service=myapp \
--label bulwark.probe.type=tcp \
--label bulwark.probe.tcp_host=localhost \
--label bulwark.probe.tcp_port=8080 \
myapp:latest
bulwark.enabled=true|false - Enable Bulwark management (required)bulwark.policy=notify|safe|aggressive - Update policy (default: safe)bulwark.tier=stateless|stateful - Service tier (default: stateless)bulwark.definition=compose:/abs/path/compose.yml#service=<service> - For loose containersbulwark.probe.type=http|tcp|log|stability - Probe typebulwark.probe.url=<url> - HTTP probe URLbulwark.probe.expect_status=<code> - Expected HTTP status (default: 200)bulwark.probe.tcp_host=<host> - TCP probe hostbulwark.probe.tcp_port=<port> - TCP probe portbulwark.probe.log_pattern=<regex> - Log pattern to matchbulwark.probe.stability_sec=<seconds> - Stability window durationBULWARK_ROOT=/docker_data - Base path for compose discoveryBULWARK_STATE_DB=/var/lib/bulwark/state.db - State database location (SQLite)BULWARK_LOG_LEVEL=debug|info|warn|error - Logging verbosityBULWARK_UI_ENABLED=true|false - Enable the Web Console (default: true)BULWARK_UI_READONLY=true|false - Read-only mode (default: true)BULWARK_WEB_TOKEN=... - Required bearer token for write actionsBULWARK_UI_ADDR=:8080 - UI/API listen addressBULWARK_UI_DIST=web/dist - Path to built UI assetsBULWARK_PLAN_CACHE_TTL=15s - Cache TTL for overview/plan calculationsBULWARK_WEB_WRITE_RPS=1 - Write endpoint rate limit (requests per second)BULWARK_WEB_WRITE_BURST=3 - Write endpoint burst capacity⚠️ Docker Socket Access: Bulwark requires access to /var/run/docker.sock, which provides full Docker daemon control. Run Bulwark in a trusted environment only.
BULWARK_WEB_TOKEN and bearer auth# Install dependencies
go mod download
# Build
make build
# Run tests
make test
# Run linter
make lint
# Build Docker image
make docker-build
MIT License - see LICENSE file for details.
Contributions welcome! Please see CONTRIBUTING.md for guidelines.
Content type
Image
Digest
sha256:2a5fab631…
Size
220.6 MB
Last updated
2 months ago
docker pull itsmrshow/bulwark