// the find
crazy-max/diun
Receive notifications when an image is updated on a Docker registry
Diun polls container registries (Docker Hub, Docker, Swarm, Kubernetes, Nomad, containerd, or static image lists) and fires a notification when a tag or digest changes. It's for people running self-hosted stacks who want to know when a base image or app image has a new build without manually diffing digests or trusting `:latest` to behave.
Provider coverage is genuinely broad — Docker, Swarm, Kubernetes, Nomad, containerd, plus file-based and Dockerfile-based watching, so it fits almost any deployment shape rather than assuming you run plain Docker. Notification backends are equally wide (Slack, Discord, Telegram, Gotify, ntfy, mail, webhook, script, AMQP, MQTT...) with per-backend test files, and there's a BoltDB-backed manifest store so it tracks what it's already seen instead of re-notifying every run. CI is unusually careful for a project this size — CodeQL, zizmor (GitHub Actions supply-chain linting), and Codecov are all wired into the workflow, and the test suite has fixtures for things like Docker secrets and registry auth edge cases.
It only tells you, it doesn't act — no auto-pull, no apply, so you still need something like Watchtower or your own script hooked to the notification to close the loop. State lives in a single BoltDB file, which is a bit of a mismatch for a tool explicitly built to watch Kubernetes and Swarm clusters — there's no clustering or shared-state story if you run Diun itself as more than one replica. The migration docs (v0→v1 through v4.1→v4.29) show the config format has broken repeatedly across major versions, so upgrading isn't always a drop-in — budget time to re-check your YAML against the migration guide before bumping majors.