Change records
Swarm Service Naming Rollout Change Record
Production panel consolidation and corrected svc stack identities.
Change metadata
- Change id:
CR-2026-08-14-swarm-service-naming-rollout - Date and time: 2026-08-14 00:22–00:40 UTC
- Environment: VPS / production
- Requester and approver: repository owner, explicit approval in the active session
- Executor: Codex
- Status: completed with one credential follow-up
Scope
- Consolidate eight administration UIs from mixed
infra-*services into one role-labeled administration stack. - Preserve panel images, external volumes, secrets, networks, routes, and desired replicas.
- Rename
infra-vaultwarden,infra-zitadel, andinfra-giteato matchingsvc-*stacks. - Keep Kener in
infra-edge. - Add guarded panel list and zero/one scaling operations.
Preconditions
- Explicit production approval captured.
- Live stack/service/image/replica baseline captured.
- Required external volumes, networks, and secrets confirmed.
- Repository manifests rendered and helper tests passed.
- External-volume rollback path confirmed.
Execution log
- The initial source-stack redeploy re-resolved floating image tags and restarted several core services. The naming rollout was paused immediately.
- PostgreSQL, MySQL, MongoDB, Kong, Redis, RabbitMQ, Traefik, and Kener were restored to
their prior image digests/specifications. All returned to
1/1; Kener returned 200, Kong returned its expected unmatched-route 404, and Gitea health remained 200. - The old eight panel services were removed directly, then recreated under the
administration-stack identity in use for this rollout, with their exact prior
image digests and external state. The source identity is now superseded by
panels; its separate production migration remains pending. - The production baseline was preserved: pgAdmin, phpMyAdmin, Mongo Express, Konga, and
Redis Insight are
0/0; Portainer, WUD, and NetBird Dashboard are1/1. - Vaultwarden, Zitadel, and Gitea were stopped and recreated one at a time as
svc-vaultwarden,svc-zitadel, andsvc-gitea, using exact prior image digests. - Launchers were hardened with literal env parsing and
--resolve-image changedto avoid shell execution of space-containing values and unrelated floating-tag upgrades.
Validation results
- All old panel and
infra-{vaultwarden,zitadel,gitea}service identities are absent. - The administration stack contained exactly eight role-labeled services at validation time.
- Controlled pgAdmin
0 → 1 → 0test passed; non-NetBird access returned 403. - Kener health: 200; Kong public root: expected 404.
- Vaultwarden
/alive: 200. - Zitadel
/debug/ready: 200; root: expected 308 redirect. - Gitea
/api/healthz: 200;/v2/: expected 401 authentication challenge. - Portainer and WUD from the server's non-NetBird source: 403; NetBird Dashboard: 200.
- All expected core and application services report
1/1; intentionally suspended services retain their prior zero-replica states.
Exception and follow-up
- An authenticated Gitea image pull returned
unauthorized; the VPS Docker client's savedsvc-pullerlogin is absent or expired. No alternate service token was reused. - Restore the dedicated
svc-pullerlogin and repeat an authenticated image pull before the next deployment requiring a private image not already cached on the node.
Rollback
The old identities can be restored from the prior repository revision after removing the new identity, using the same external volumes, networks, and secrets. No rollback was required after final validation.
Outcome
- Result: successful naming rollout with one non-blocking registry-login follow-up.
- Data integrity: no data loss observed; all stateful services reused existing external data.
Swarm Role Layout Production Rollout
Production migration to role-organized split stacks and canonical operations tooling.
Traefik Dashboard Retirement And Traefik Manager Rollout
Disabled the built-in Traefik dashboard and replaced it with Traefik Manager behind NetBird, with file-scoped config ownership and access logging.