Perspective V Docs

Operations Stack Guide

The operations stack owns update automation, update visibility, and the outbound SSH policy helper.

In the active Swarm layout, Watchtower belongs to the shared platform stack and WUD is an administration panel. The retained Compose layout below remains combined; the SSH egress helper remains beside that host-specific runtime configuration.

Source Of Truth

  • Active Swarm Watchtower: swarm/stacks/platform/watchtower/{watchtower,watchtower-fast}.yml (platform)

  • Active Swarm launcher: swarm/scripts/platform/platform.{sh,bat}

  • Active WUD panel: swarm/stacks/panels/wud.yml (panel)

  • Canonical host-wide operations: operations/

  • Compose: runtime/stacks/infrastructure/operations/docker-compose.operations.yml

  • VPS env: runtime/environments/vps/infrastructure/operations/.env

  • VPS placeholder: runtime/environments/vps/infrastructure/operations/operations.env

  • Dev template: runtime/environments/dev/infrastructure/operations/operations.dev.env

  • Launcher: runtime/scripts/infrastructure/operations.{sh,bat}

  • Host policy helper: runtime/stacks/infrastructure/operations/ssh-egress-policy.sh

Services

  • watchtower
  • watchtower-fast
  • wud

Required Variables

  • DOCKER_API_VERSION=1.40
  • WATCHTOWER_SCHEDULE
  • WATCHTOWER_DEFAULT_SCOPE
  • WATCHTOWER_FAST_SCOPE
  • WATCHTOWER_FAST_INTERVAL
  • WUD_HOST
  • WUD_WATCHER_LOCAL_CRON
  • WUD_WATCHER_LOCAL_WATCHBYDEFAULT
  • WUD_REGISTRY_CUSTOM_PV_URL
  • WUD_REGISTRY_CUSTOM_PV_LOGIN
  • WUD_REGISTRY_CUSTOM_PV_PASSWORD
  • WUD_TRIGGER_DISCORD_MAIN_URL

Deploy

./runtime/scripts/infrastructure/operations.sh up

Raw compose command:

docker compose --env-file runtime/environments/vps/infrastructure/operations/.env -f runtime/stacks/infrastructure/operations/docker-compose.operations.yml up -d

Validate

./runtime/scripts/infrastructure/operations.sh ps
./runtime/scripts/infrastructure/operations.sh logs
curl -Ik https://wud.perspective-v.com
curl -s -X POST http://127.0.0.1:3000/api/containers/watch

SSH Egress Policy

Default deny and status:

sudo bash runtime/stacks/infrastructure/operations/ssh-egress-policy.sh enforce-default
sudo bash runtime/stacks/infrastructure/operations/ssh-egress-policy.sh status

GitHub over SSH 443:

sudo bash runtime/stacks/infrastructure/operations/ssh-egress-policy.sh github-443-setup --user root
bash runtime/stacks/infrastructure/operations/ssh-egress-policy.sh github-443-test

Watchtower/WUD policy:

  • Stateless services use Watchtower labels.
  • Stateful services stay manual-update.
  • WUD stays alerting-only.

On this page