Skip to content

Linux Docker Operations

Recommended Linux container production path: offline prebuilt OCI image + external MongoDB. Customer host needs Docker Engine and Compose v2 only.

Repository scripts: scripts/linux/docker. The GitHub Release tarball iqv-integration-api-<version>-linux-docker-amd64.tar.gz exposes them as scripts/*.sh and includes image/*.tar.

Prerequisites

  • Docker Engine already installed (the package does not install Docker)
  • Compose plugin (docker compose)
  • amd64 host
  • External MongoDB reachable from the container network (not loopback)

Inspect

bash docker ps docker inspect <container> docker compose ps sudo ./scripts/status.sh

Restart policy: unless-stopped. Production compose uses pull_policy: never, no build:, user: "10001:10001".

Logs

bash docker logs <container> docker logs -f <container> docker compose logs -f

Driver: json-file, max-size: 10m, max-file: 5.

Offline docker load

Install/update verifies SHA256SUMS / image tar checksum, then docker load -i image/*.tar. There is no registry pull and no docker build on the production path. Checksum mismatch does not load or mutate.

External MongoDB

The installer never rewrites MONGODB_URI to host.docker.internal. Production compose has no extra_hosts. Use a real host/IP:

text MONGODB_URI=mongodb://<MONGODB_HOST>:27017 MONGODB_DATABASE=<DATABASE_NAME>

Port resolution

--host-port / --container-port (defaults follow package/env; do not assume 4242 unless you set it). HostPort occupancy uses real LISTEN rows, not ss headers.

Status / update / ForceRedeploy / rollback

bash sudo ./scripts/status.sh sudo ./scripts/update.sh sudo ./scripts/update.sh --force-redeploy

Decision is loaded image id. Same id ⇒ NO-OP (no restart). --force-redeploy runs docker compose up -d --no-build --force-recreate. Failed health restores the immutable snapshot image. External MongoDB is not modified.

Lab-only: --test-fail-at AfterComposeUp.

Auto-update (optional, default disabled)

Units: iqv-integration-api-updater.service + .timer (OnBootSec=5min, OnUnitActiveSec=15min).

bash sudo ./scripts/enable-auto-update.sh sudo ./scripts/disable-auto-update.sh

Auto-update discovers a versioned release manifest, verifies SHA256, and reuses update.sh. It is not git pull. It stays disabled until explicitly enabled and AUTO_UPDATE_SOURCE is set.

Uninstall

bash sudo ./scripts/uninstall.sh sudo ./scripts/uninstall.sh --remove-images sudo ./scripts/uninstall.sh --purge

compose down does not pass --volumes. Docker Engine is never removed. See Uninstall.