Skip to content

Auto Label

  • This container puts a label on each machine based on a config that matches service names.
  • If the service is running on a node the label gets a 1, and if it isn't the label gets a 0.
  • this can be used with constraints to either locate services on a node with another service OR make sure a service doesn't land on a node with another service

I would love to find a better version of this that does this without the need for the manual config file (you can use a file bindmount instead of a config if you prefer)

Swarm Consideration

  • State is all read-only in a config.
  • This runs as one replica on a manager and sets the labels on every node.
  • The config is servicelist.txt in git. It deploys as a swarm config with a version in its name, see stack conventions.

Stack

compose.yml, 26 lines, 1 note

each in the code opens a note on that line. download compose.yml

version: "3.7"
services:
  dockerautolabel:
    build: .
    image: davideshay/dockerautolabel:latest
    environment:
      - TZ=America/Los_Angeles
    volumes:
      - type: bind
        source: /usr/share/zoneinfo
        target: /usr/share/zoneinfo
        read_only: true
      - /var/run/docker.sock:/var/run/docker.sock
    configs:
      - source: dockerautolabel_config
        target: /config/servicelist.txt
    deploy:
      mode: replicated
      replicas: 1
      placement:
        constraints: [ node.role == manager]

configs:
  dockerautolabel_config:  # (1)!
    file: ./servicelist.txt
    name: dockerautolabel_config_v4
  1. the service list is servicelist.txt, below, deployed as a swarm config. swarm refuses a deploy that changes a config's content under the same name, so each change to the list bumps the version suffix on the config's name.

Config

  • This is the name of the service when running followed by what you want the label to say.
  • Use sudo docker service ls to get the names.
servicelist.txt: each service, and the label it sets, 16 lines

download servicelist.txt

adguard_adguard1,running_adguard1
adguard_adguard2,running_adguard2
adguard_adguardhome-sync,running_adguardhome-sync
agent_agent,running_agent
apprise_apprise-api,running_apprise-api
cloudflare-ddns_cloudflare-ddns,running_cloudflare-ddns
dockerproxy_dockerproxy,running_dockerproxy
infinitude_infinitude,running_infinitude
mqtt_mosquitto,running_mosquitto
npm_app,running_npm
npm_db,running_npm_db
oauth_oauth2-proxy,running_oauth2-proxy
portainer_portainer,running_portainer
unifiapibrowser_unifiapibrowser,running_unifiapibrowser
wordpress2025_db,running_wordpress_db
wordpress2025_wordpress,running_wordpress

How i use this with adguard to make sure adguard 1 and 2 don't run on the same node EVER (which causes failure conditions)

...
  adguard2:
    ...
    deploy:
      mode: replicated
      replicas: 1
      placement:
        constraints: [node.labels.running_adguard1 == 0]
...

This page started as a gist: the original, with its comments