Compose Runtime Reference
Retained Docker Compose rebuild and rollback reference for the active Swarm deployment.
This guide documents the retained Compose implementation. The active VPS
control plane is Docker Swarm; use swarm/README.md and
Docker Swarm Migration for current deployment commands.
The retained Compose layout is:
- Compose files stay under
runtime/stacks. - Live VPS runtime values stay in local
.envfiles underruntime/environments/vps. - Tracked placeholder values stay in named
*.envfiles underruntime/environments/vps. - Reproducible non-production values stay in
runtime/environments/dev/**/*.dev.env. - Repeatable launcher scripts stay under
runtime/scripts.
Related guides:
- runtime-environments-guide.md
- runtime-ci-guide.md
- runtime-wrapper-scripts-guide.md
- stack-edge-guide.md
- stack-homelab-guide.md
- stack-platform-guide.md
- stack-operations-guide.md
- stack-gitea-guide.md
- stack-databases-guide.md
- stack-netbird-guide.md
- stack-gateway-guide.md
- stack-object-storage-guide.md
- service-stacks-guide.md
- kong-route-service-mapping-guide.md
1. Host Baseline
Run on the VPS:
export PLAN_DIR="/opt/docs"
sudo apt update
sudo apt install -y curl jq ufw netcat-openbsd dnsutils
docker --version
docker compose version
dig +short netbird.perspective-v.com A
dig +short netbird.perspective-v.com AAAAApply the public firewall baseline before the runtime rollout:
sudo ufw allow OpenSSH
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw allow 3478/udp comment 'NetBird STUN/TURN'
sudo ufw --force enable
sudo ufw status numbered2. Prepare Shared Docker Resources
docker network create proxy || true
docker network create platform || true
docker network create object-storage || true
docker network create postgres-network || true
docker network create mssql-network || true
sudo mkdir -p /var/lib/traefik/letsencrypt
sudo touch /var/lib/traefik/letsencrypt/acme.json
sudo chmod 600 /var/lib/traefik/letsencrypt/acme.json
sudo mkdir -p /var/lib/rustfs/data /var/lib/rustfs/logs
sudo chown -R 10001:10001 /var/lib/rustfs/data /var/lib/rustfs/logs
sudo chmod 750 /var/lib/rustfs/data /var/lib/rustfs/logs3. Fill Runtime Environment Files
For VPS execution, create or update the local .env files under runtime/environments/vps/**.
For a new non-production Docker host, start from the matching files under runtime/environments/dev/** and run the launchers in dev mode.
Start here:
4. Rollout Order
Run the stacks in this order.
4.1 Edge Traefik And Portainer
cd "$PLAN_DIR"
./runtime/scripts/infrastructure/edge-traefik.sh up
./runtime/scripts/infrastructure/edge-portainer.sh upGuide:
4.2 NetBird Install And Sync
Initial NetBird install still uses the official quickstart script under /opt/netbird.
Guide:
4.3 Platform
cd "$PLAN_DIR"
./runtime/scripts/infrastructure/platform.sh up
./runtime/scripts/infrastructure/edge-kener.sh upGuides:
4.4 Operations
cd "$PLAN_DIR"
./runtime/scripts/infrastructure/operations.sh upGuide:
4.5 Gitea Package Registry
Gitea is the single package registry (Docker + npm + NuGet), replacing the retired docker-registry, registry-admin, ProGet, BaGet and Verdaccio services. It is deployed via the swarm launcher:
cd "$PLAN_DIR"
./swarm/scripts/services/service.sh deployGuide:
4.7 Databases
cd "$PLAN_DIR"
./runtime/scripts/infrastructure/mssql.sh up
./runtime/scripts/infrastructure/postgres.sh up postgres
./runtime/scripts/infrastructure/mysql.sh up mysql
./runtime/scripts/infrastructure/mongodb.sh up mongodb
./runtime/scripts/infrastructure/postgres.sh compose vps --profile admin up -d pgadmin
./runtime/scripts/infrastructure/mysql.sh compose vps --profile admin up -d phpmyadmin
./runtime/scripts/infrastructure/mongodb.sh compose vps --profile admin up -d mongo-expressGuide:
4.8 Gateway
Deploy PostgreSQL first, then Kong/Konga, then apply the route bootstrap or decK sync.
cd "$PLAN_DIR"
./runtime/scripts/infrastructure/gateway.sh upGuides:
4.9 Object Storage
cd "$PLAN_DIR"
./runtime/scripts/infrastructure/rustfs.sh upGuide:
4.10 Service Stacks
cd "$PLAN_DIR"
./runtime/scripts/services/identity.sh up
./runtime/scripts/services/graph.sh up
./runtime/scripts/services/console.sh up
./runtime/scripts/services/dbskc.sh up
./runtime/scripts/services/nishatcolony.sh upGuide:
5. Final Validation
Run these checks before calling the rebuild complete:
./runtime/scripts/infrastructure/edge-traefik.sh ps
./runtime/scripts/infrastructure/platform.sh ps
./runtime/scripts/infrastructure/operations.sh ps
./runtime/scripts/infrastructure/postgres.sh ps
./runtime/scripts/infrastructure/gateway.sh ps
./runtime/scripts/infrastructure/rustfs.sh ps
docker ps --format 'table {{.Names}}\t{{.Status}}'
curl -Ik https://gitea.perspective-v.com
curl -Ik https://gitea.perspective-v.com/v2/
curl -Ik https://gitea.perspective-v.com/api/packages/perspective-v/nuget/index.json
curl -Ik https://api.perspective-v.com
curl -Ik https://console.perspective-v.com
curl -Ik https://dbskc.com
curl -Ik https://nishatcolony.pkNetBird-only routes and DB ports still need client-side validation from a connected peer.
6. CI Follow-Up
After the runtime is up, configure or update the service repositories to publish images into the Gitea registry (gitea.perspective-v.com/perspective-v/<image>) using the templates under runtime/ci.
Guide: