dockge: parameterize stacks-root path + deploy on corviduo-dev
Made the host-stacks bind-mount path configurable via DOCKGE_HOST_STACKS_ROOT (default /opt/docker, unchanged for the existing five hosts). Override on corviduo-dev to /home/vh/docker because that host's /opt/ is owned by deploy:deploy (Worldtree team) and vh lacks passwordless sudo for the fleet-standard path — same reasoning as the beszel + dozzle agent placement earlier today. Deployed to corviduo-dev. Reachable at http://10.250.50.152:5001 (first probe 200 — Docker's port-mapping route through iptables worked without firewall changes, unlike beszel's network_mode: host). Scoped to PFI-managed stacks only (/home/vh/docker/compose/) — does NOT see /opt/worldtree*/ deployments. Keeps the management boundary clean: dockge can restart/recreate PFI's beszel+dozzle+itself but not the Worldtree-team-owned containers.
This commit is contained in:
@@ -68,6 +68,7 @@ future infra-ops sessions find them.
|
||||
|---|---|---|
|
||||
| `/home/vh/docker/compose/beszel/` | `beszel-agent` (host port 45876, `network_mode: host`) | Agent for the Beszel hub at ana-docker:8090. Hub SSH-polls inbound using the seeded ed25519 pubkey. |
|
||||
| `/home/vh/docker/compose/dozzle-agent/` | `dozzle-agent` (host port 7007) | Agent for the Dozzle hub at ana-docker:8088. Hub connects inbound over mTLS (auto-generated certs on first run). |
|
||||
| `/home/vh/docker/compose/dockge/` | `dockge` (host port 5001) | Per-host compose UI. Scoped to PFI-managed stacks under `/home/vh/docker/compose/` — does NOT see `/opt/worldtree*/` (worldtree-team boundary). `DOCKGE_HOST_STACKS_ROOT=/home/vh/docker` overrides the fleet-default `/opt/docker`. |
|
||||
|
||||
The empty `traefik-net` external docker network was created on this host as
|
||||
a side effect of dozzle-agent's compose (which declares it external). Future
|
||||
|
||||
Reference in New Issue
Block a user