Operations Stack Guide
The operations stack owns update automation, update visibility, and the outbound SSH policy helper.
In the active Swarm layout, Watchtower belongs to the shared platform stack and WUD is an
administration panel. The retained Compose layout below remains combined; the
SSH egress helper remains beside that host-specific runtime configuration.
Source Of Truth
-
Active Swarm Watchtower:
swarm/stacks/platform/watchtower/{watchtower,watchtower-fast}.yml(platform) -
Active Swarm launcher:
swarm/scripts/platform/platform.{sh,bat} -
Active WUD panel:
swarm/stacks/panels/wud.yml(panel) -
Canonical host-wide operations:
operations/ -
Compose:
runtime/stacks/infrastructure/operations/docker-compose.operations.yml -
VPS env:
runtime/environments/vps/infrastructure/operations/.env -
VPS placeholder:
runtime/environments/vps/infrastructure/operations/operations.env -
Dev template:
runtime/environments/dev/infrastructure/operations/operations.dev.env -
Launcher:
runtime/scripts/infrastructure/operations.{sh,bat} -
Host policy helper:
runtime/stacks/infrastructure/operations/ssh-egress-policy.sh
Services
watchtowerwatchtower-fastwud
Required Variables
DOCKER_API_VERSION=1.40WATCHTOWER_SCHEDULEWATCHTOWER_DEFAULT_SCOPEWATCHTOWER_FAST_SCOPEWATCHTOWER_FAST_INTERVALWUD_HOSTWUD_WATCHER_LOCAL_CRONWUD_WATCHER_LOCAL_WATCHBYDEFAULTWUD_REGISTRY_CUSTOM_PV_URLWUD_REGISTRY_CUSTOM_PV_LOGINWUD_REGISTRY_CUSTOM_PV_PASSWORDWUD_TRIGGER_DISCORD_MAIN_URL
Deploy
./runtime/scripts/infrastructure/operations.sh upRaw compose command:
docker compose --env-file runtime/environments/vps/infrastructure/operations/.env -f runtime/stacks/infrastructure/operations/docker-compose.operations.yml up -dValidate
./runtime/scripts/infrastructure/operations.sh ps
./runtime/scripts/infrastructure/operations.sh logs
curl -Ik https://wud.perspective-v.com
curl -s -X POST http://127.0.0.1:3000/api/containers/watchSSH Egress Policy
Default deny and status:
sudo bash runtime/stacks/infrastructure/operations/ssh-egress-policy.sh enforce-default
sudo bash runtime/stacks/infrastructure/operations/ssh-egress-policy.sh statusGitHub over SSH 443:
sudo bash runtime/stacks/infrastructure/operations/ssh-egress-policy.sh github-443-setup --user root
bash runtime/stacks/infrastructure/operations/ssh-egress-policy.sh github-443-testWatchtower/WUD policy:
- Stateless services use Watchtower labels.
- Stateful services stay manual-update.
- WUD stays alerting-only.