The simplest production setup.
WHAT IT LOOKS LIKE
One server, running containers, with a reverse proxy in front.
WHAT THE PROXY DOES
Terminates encryption Routes by hostname to the right container Handles certificates
WHY A PROXY RATHER THAN PUBLISHING PORTS DIRECTLY
Several applications can share ports eighty and four hundred and forty-three.
WHAT TO AUTOMATE
Certificate issuance and renewal.
WHAT TO USE FOR ORCHESTRATION AT THIS SCALE
A compose file, or systemd units.
WHY NOT SOMETHING LARGER
A cluster manager for one host adds complexity without benefit.
WHAT THE DEPLOYMENT PROCESS SHOULD BE
Pull the new image Start the new container Confirm it is healthy Switch traffic Remove the old
WHAT THAT ACHIEVES
Deployment without downtime.
WHAT TO KEEP
The previous image, so reverting is immediate.
WHAT TO AUTOMATE
The whole sequence, in a script under version control.
WHAT TO MONITOR
Container health Host resources Disk, which fills with images and logs
WHAT TO SCHEDULE
Cleanup of unused images and volumes.
WHY
It is the commonest cause of a full disk on container hosts.
WHAT TO BACK UP
Volumes, and the configuration describing the setup.