Databases Stack Guide
The databases stack owns the engine containers, admin UIs, backup helpers, and NetBird firewall cutover workflow.
The active Swarm database stack owns only the engines. Their administration UIs
belong to the panel stack; the retained Compose layout below still exposes
admin profiles for rollback and local development.
Source Of Truth
-
Active Swarm engines:
swarm/stacks/databases/<engine>.yml -
Active Swarm launcher:
swarm/scripts/databases/database.{sh,bat} -
Active database panels:
swarm/stacks/panels/{pgadmin,phpmyadmin,mongo-express}.yml -
Compose files:
runtime/stacks/infrastructure/databases/mssql/docker-compose.mssql.ymlruntime/stacks/infrastructure/databases/postgres/docker-compose.postgres.ymlruntime/stacks/infrastructure/databases/mysql/docker-compose.mysql.ymlruntime/stacks/infrastructure/databases/mongodb/docker-compose.mongodb.yml
-
VPS env files:
runtime/environments/vps/infrastructure/databases/{mssql,postgres,mysql,mongodb}/.env
-
Dev templates:
runtime/environments/dev/infrastructure/databases/{mssql,postgres,mysql,mongodb}/*.dev.env
-
Launchers:
runtime/scripts/infrastructure/{mssql,postgres,mysql,mongodb}.{sh,bat}
Access Model
- DB engine ports are direct TCP and must be limited to NetBird.
- DB UIs are HTTPS routes behind Traefik and must be NetBird-only.
- Containers use internal DB hostnames:
mssql,postgres,mysql,mongodb. - Developer machines use friendly FQDNs over NetBird.
Pre-Checks
- NetBird server peer is healthy.
- Required developer peers are connected.
proxyandpostgres-networkexist.- DB env values are finalized.
Detect the NetBird interface before cutover:
ip -br link | awk '$1 ~ /^wt/ {print $1}'
ip -4 -br addr show wt0Deploy Engines
./runtime/scripts/infrastructure/mssql.sh up
./runtime/scripts/infrastructure/postgres.sh up postgres
./runtime/scripts/infrastructure/mysql.sh up mysql
./runtime/scripts/infrastructure/mongodb.sh up mongodbDeploy Admin UIs
./runtime/scripts/infrastructure/postgres.sh compose vps --profile admin up -d pgadmin
./runtime/scripts/infrastructure/mysql.sh compose vps --profile admin up -d phpmyadmin
./runtime/scripts/infrastructure/mongodb.sh compose vps --profile admin up -d mongo-expressRaw compose equivalents:
docker compose --env-file runtime/environments/vps/infrastructure/databases/postgres/.env -f runtime/stacks/infrastructure/databases/postgres/docker-compose.postgres.yml --profile admin up -d pgadmin
docker compose --env-file runtime/environments/vps/infrastructure/databases/mysql/.env -f runtime/stacks/infrastructure/databases/mysql/docker-compose.mysql.yml --profile admin up -d phpmyadmin
docker compose --env-file runtime/environments/vps/infrastructure/databases/mongodb/.env -f runtime/stacks/infrastructure/databases/mongodb/docker-compose.mongodb.yml --profile admin up -d mongo-expressStop And Remove
./runtime/scripts/infrastructure/mssql.sh down
./runtime/scripts/infrastructure/postgres.sh compose vps --profile admin down --remove-orphans
./runtime/scripts/infrastructure/mysql.sh compose vps --profile admin down --remove-orphans
./runtime/scripts/infrastructure/mongodb.sh compose vps --profile admin down --remove-orphansAdd -v only when you intentionally want to delete volumes.
Firewall Cutover
Run only after NetBird validation:
cd runtime/stacks/infrastructure/netbird
chmod +x db-port-cutover.sh
NB_IFACE=wt0 ./db-port-cutover.shValidate
From a NetBird-connected client:
nc -vz mssql.perspective-v.com 1433
nc -vz pgsql.perspective-v.com 5432
nc -vz mysql.perspective-v.com 3306
nc -vz mongo.perspective-v.com 27017
curl -Ik https://pgadmin.perspective-v.com
curl -Ik https://phpmyadmin.perspective-v.com
curl -Ik https://mongo-express.perspective-v.comBackup And Restore Helpers
operations/backups/db-backup.shoperations/backups/postgres-physical-backup.shoperations/restore/postgres-restore.shoperations/systemd/tier1-db-backup/install.shoperations/systemd/postgres-physical-backup/install.shoperations/diagnostics/collect-tier1-backup-evidence.shoperations/backups/tier1-offsite-sync.sh
Examples:
operations/backups/db-backup.sh run --keep-last-backups 3
sudo operations/systemd/tier1-db-backup/install.sh
sudo operations/diagnostics/collect-tier1-backup-evidence.sh
operations/backups/db-backup.sh upload --dry-run --env-file /etc/contabo-backups/backup.env
operations/backups/postgres-physical-backup.sh run --offsite --dry-run \
--env-file /etc/contabo-backups/backup.envThe weekly helper discovers active Swarm tasks and writes PostgreSQL globals plus one
custom dump for every connectable non-template database, including postgres. It also
backs up every non-system MySQL database and the MongoDB cluster. MSSQL remains supported
but is excluded from the current schedule while its service is 0/0. Encrypted Google
Drive delivery is gated by DB_OFFSITE_ENABLED=true; source, upload, or verification
failures retain staging and exit non-zero.
The monthly physical helper uses online pg_basebackup, included WAL, gzip/tar, and a
native SHA-256 backup manifest. It retains two local and four verified remote snapshots.
Use the guarded restore helper to validate logical dumps or rebuild an isolated
PostgreSQL 18 scratch volume; it never changes the production Swarm service or volume.