Skip to content

Uninstall

The uninstall is a single command and cleans up only resources belonging to IQV Platform. It does not touch other projects' containers/networks/images, and no global destructive commands such as docker system prune are used.

powershell -ExecutionPolicy Bypass -File .\scripts\windows\uninstall.ps1
sudo ./scripts/linux/uninstall.sh

What is removed?

Docker mode: the containers created under the -p iqv-platform project name, the project network and the images are stopped and removed.

Native mode: the service/task definitions (systemd unit + Nginx site / Windows Scheduled Task) are stopped, disabled and deleted; the generated build/runtime files are cleaned up.

Options and safety boundaries

Windows Linux Behaviour
-PurgeData --purge-data Deletes only the local Docker volumes belonging to this project. It never touches external MongoDB/MinIO/SMTP data.
-RemoveCode --remove-code Deletes the application code (the repository directory).
-DryRun --dry-run Shows what would be deleted, deletes nothing.
-Yes --yes Non-interactive (no confirmation prompt).

Deleting code and deleting data are separate

--remove-code deletes only the code, --purge-data deletes only this project's local volumes. The two are deliberately separated; an operation that risks data loss must be requested on its own and explicitly.

Self-delete protection

If --remove-code is run from inside the directory that is to be deleted, it is rejected for safety reasons (Windows/Linux file locking and self-deletion problems). In that case the script prints the correct command to run from outside the repository:

cd /tmp && sudo '/opt/iqv-platform/scripts/linux/uninstall.sh' --mode docker --remove-code --yes

Installation root validation (recursive delete guard)

--remove-code / -RemoveCode never performs a recursive delete on an unvalidated path. Before deleting, the target path must pass the checks below; if even one of them fails, the operation is rejected and nothing is deleted:

  • The path must not be empty and must be absolute (a relative path is rejected).
  • The path must be an existing directory (a file is rejected).
  • The filesystem root (/, C:\) and any drive/share root is rejected.
  • System directories are rejected (/usr, /var, /home, /tmp, %SystemRoot%, %ProgramFiles%, %ProgramData%, %USERPROFILE% …).
  • The path must be at least two levels deep (single-level roots such as /opt are rejected).
  • The target must carry the IQV signature: docker-compose.yml, backend/, dashboard/ and the corresponding scripts/<platform>/lib.* file must all be present. A partial signature is not sufficient.

This makes rm -rf /-like behaviour structurally impossible, even if an environment variable arrives empty or incorrect.

Idempotency

On a system that has already been uninstalled it does not produce a stack trace: situations such as "container already removed" or "service not found" are reported in a controlled way and the exit code is successful.