Container & Compose file
The two extra screens a container application gets — image, network, limits and volumes, and the compose file that actually runs it.
An application installed as a container — Ghost, Gitea, Vaultwarden and the
rest of the container catalogue — gets two screens no other type has:
Container and Compose file. In exchange it loses
Environment and
PHP Settings: a container
has no .env screen because its environment lives in the compose file, and
no PHP because it does not run on the server's PHP.
Only on a container server
Whether a server can host containers is fixed when the panel is installed,
by the stack you choose. A lemp, lamp or ols server serves PHP and
static sites; only a docker server serves containers. You cannot convert
one into the other afterwards — on a PHP server the Server → Docker
page simply says "Not a container server", and the container application
types are hidden from the create form.
The screenshots for these two screens are therefore taken on a separate container-stack server, and live with the container application types rather than here.
Container
One form, four things.
Image
The image the site runs. It is read-only here: "Changed by redeploying the site, not here — a new image is pulled before the old container is replaced."
Network
Which Docker network the container joins.
Containers on the same network reach each other by name; Docker's default bridge cannot do that, which is why the panel creates networks of its own. The screen tells you the hostname other containers should use for this site — and warns against one in particular:
Avoid "app": every site the panel builds answers to that name, so it resolves to an arbitrary one of them.
If the network a site is set to join has been deleted, the container will not start, and the screen says exactly that rather than letting you guess.
Limits
| Field | Notes |
|---|---|
| Container port | The port your application listens on inside the container. |
| Memory limit | e.g. 512m or 2g. A bare number means bytes, not megabytes. Empty uses the server default. |
| CPU limit | In cores — 1 for one full core, 0.5 for half. You cannot set more than the server has. Empty means no limit. |
The two limits fail in opposite ways
Both are ceilings for this container alone, not reservations — nothing is set aside for it. Past the memory ceiling the container is killed and restarted, so the site drops requests. Past the CPU quota nothing is killed and the container simply waits, so the site is slow with no error anywhere. Knowing which symptom belongs to which limit saves an afternoon.
Volumes
A volume keeps data that survives the container being rebuilt. Mount one by
picking a volume and giving an absolute path inside the container, e.g.
/var/lib/mysql.
With no volumes mounted, the screen is blunt: "The container keeps nothing that survives a rebuild."
A freshly mounted volume is empty
Mounting hides whatever the image had at that path — it is not merged. The container is recreated, and it starts with an empty directory there.
Volumes and networks themselves are created on Server → Docker.
Generated credentials
For one-click container apps the panel generated database credentials at install time and keeps them encrypted. Reveal shows them, and revealing them is written to the activity log. They are the application's real credentials and cannot be changed from here — the running database would keep the old value.
Save container settings recreates the container, so the site is down for a few seconds.
Compose file
The compose file is what actually runs the site. Environment variables, extra services and extra volumes all live here — this is the screen that replaces the Environment screen.
The editor is checked by Docker's own parser before anything is applied, and the panel refuses a file that:
- publishes a port on anything other than
127.0.0.1, or - mounts a path outside this site's own directory.
If the new file will not come up, the panel puts the previous one back and starts the site on that, so a bad edit does not leave you with a stopped site.
Saving here is one-way
Until you save, the site runs a compose file the panel generates from the Image and Container port fields on the Container screen. Saving takes the file over permanently: from then on the text in this editor is what runs, and those fields stop driving it. The panel makes you tick "I understand that saving replaces the generated file permanently" before it will apply it. The only way back is to clear the file entirely.