ServerAvatarDocs
ApplicationsManaging an application

Container & Compose file

The two extra screens a container application gets — image, network, limits and volumes, and the compose file that actually runs it.

An application installed as a container — Ghost, Gitea, Vaultwarden and the rest of the container catalogue — gets two screens no other type has: Container and Compose file. In exchange it loses Environment and PHP Settings: a container has no .env screen because its environment lives in the compose file, and no PHP because it does not run on the server's PHP.

Only on a container server

Whether a server can host containers is fixed when the panel is installed, by the stack you choose. A lemp, lamp or ols server serves PHP and static sites; only a docker server serves containers. You cannot convert one into the other afterwards — on a PHP server the Server → Docker page simply says "Not a container server", and the container application types are hidden from the create form.

The screenshots for these two screens are therefore taken on a separate container-stack server, and live with the container application types rather than here.

Container

One form, four things.

Image

The image the site runs. It is read-only here: "Changed by redeploying the site, not here — a new image is pulled before the old container is replaced."

Network

Which Docker network the container joins.

Containers on the same network reach each other by name; Docker's default bridge cannot do that, which is why the panel creates networks of its own. The screen tells you the hostname other containers should use for this site — and warns against one in particular:

Avoid "app": every site the panel builds answers to that name, so it resolves to an arbitrary one of them.

If the network a site is set to join has been deleted, the container will not start, and the screen says exactly that rather than letting you guess.

Limits

FieldNotes
Container portThe port your application listens on inside the container.
Memory limite.g. 512m or 2g. A bare number means bytes, not megabytes. Empty uses the server default.
CPU limitIn cores — 1 for one full core, 0.5 for half. You cannot set more than the server has. Empty means no limit.

The two limits fail in opposite ways

Both are ceilings for this container alone, not reservations — nothing is set aside for it. Past the memory ceiling the container is killed and restarted, so the site drops requests. Past the CPU quota nothing is killed and the container simply waits, so the site is slow with no error anywhere. Knowing which symptom belongs to which limit saves an afternoon.

Volumes

A volume keeps data that survives the container being rebuilt. Mount one by picking a volume and giving an absolute path inside the container, e.g. /var/lib/mysql.

With no volumes mounted, the screen is blunt: "The container keeps nothing that survives a rebuild."

A freshly mounted volume is empty

Mounting hides whatever the image had at that path — it is not merged. The container is recreated, and it starts with an empty directory there.

Volumes and networks themselves are created on Server → Docker.

Generated credentials

For one-click container apps the panel generated database credentials at install time and keeps them encrypted. Reveal shows them, and revealing them is written to the activity log. They are the application's real credentials and cannot be changed from here — the running database would keep the old value.

Save container settings recreates the container, so the site is down for a few seconds.

Compose file

The compose file is what actually runs the site. Environment variables, extra services and extra volumes all live here — this is the screen that replaces the Environment screen.

The editor is checked by Docker's own parser before anything is applied, and the panel refuses a file that:

  • publishes a port on anything other than 127.0.0.1, or
  • mounts a path outside this site's own directory.

If the new file will not come up, the panel puts the previous one back and starts the site on that, so a bad edit does not leave you with a stopped site.

Saving here is one-way

Until you save, the site runs a compose file the panel generates from the Image and Container port fields on the Container screen. Saving takes the file over permanently: from then on the text in this editor is what runs, and those fields stop driving it. The panel makes you tick "I understand that saving replaces the generated file permanently" before it will apply it. The only way back is to clear the file entirely.

On this page