Perspective V Docs
Change records

Swarm Service Naming Rollout Change Record

Production panel consolidation and corrected svc stack identities.

Change metadata

  • Change id: CR-2026-08-14-swarm-service-naming-rollout
  • Date and time: 2026-08-14 00:22–00:40 UTC
  • Environment: VPS / production
  • Requester and approver: repository owner, explicit approval in the active session
  • Executor: Codex
  • Status: completed with one credential follow-up

Scope

  • Consolidate eight administration UIs from mixed infra-* services into one role-labeled administration stack.
  • Preserve panel images, external volumes, secrets, networks, routes, and desired replicas.
  • Rename infra-vaultwarden, infra-zitadel, and infra-gitea to matching svc-* stacks.
  • Keep Kener in infra-edge.
  • Add guarded panel list and zero/one scaling operations.

Preconditions

  • Explicit production approval captured.
  • Live stack/service/image/replica baseline captured.
  • Required external volumes, networks, and secrets confirmed.
  • Repository manifests rendered and helper tests passed.
  • External-volume rollback path confirmed.

Execution log

  1. The initial source-stack redeploy re-resolved floating image tags and restarted several core services. The naming rollout was paused immediately.
  2. PostgreSQL, MySQL, MongoDB, Kong, Redis, RabbitMQ, Traefik, and Kener were restored to their prior image digests/specifications. All returned to 1/1; Kener returned 200, Kong returned its expected unmatched-route 404, and Gitea health remained 200.
  3. The old eight panel services were removed directly, then recreated under the administration-stack identity in use for this rollout, with their exact prior image digests and external state. The source identity is now superseded by panels; its separate production migration remains pending.
  4. The production baseline was preserved: pgAdmin, phpMyAdmin, Mongo Express, Konga, and Redis Insight are 0/0; Portainer, WUD, and NetBird Dashboard are 1/1.
  5. Vaultwarden, Zitadel, and Gitea were stopped and recreated one at a time as svc-vaultwarden, svc-zitadel, and svc-gitea, using exact prior image digests.
  6. Launchers were hardened with literal env parsing and --resolve-image changed to avoid shell execution of space-containing values and unrelated floating-tag upgrades.

Validation results

  • All old panel and infra-{vaultwarden,zitadel,gitea} service identities are absent.
  • The administration stack contained exactly eight role-labeled services at validation time.
  • Controlled pgAdmin 0 → 1 → 0 test passed; non-NetBird access returned 403.
  • Kener health: 200; Kong public root: expected 404.
  • Vaultwarden /alive: 200.
  • Zitadel /debug/ready: 200; root: expected 308 redirect.
  • Gitea /api/healthz: 200; /v2/: expected 401 authentication challenge.
  • Portainer and WUD from the server's non-NetBird source: 403; NetBird Dashboard: 200.
  • All expected core and application services report 1/1; intentionally suspended services retain their prior zero-replica states.

Exception and follow-up

  • An authenticated Gitea image pull returned unauthorized; the VPS Docker client's saved svc-puller login is absent or expired. No alternate service token was reused.
  • Restore the dedicated svc-puller login and repeat an authenticated image pull before the next deployment requiring a private image not already cached on the node.

Rollback

The old identities can be restored from the prior repository revision after removing the new identity, using the same external volumes, networks, and secrets. No rollback was required after final validation.

Outcome

  • Result: successful naming rollout with one non-blocking registry-login follow-up.
  • Data integrity: no data loss observed; all stateful services reused existing external data.

On this page