Containers and volumes
The containers and Docker volumes that make up a Workforce Intelligence deployment, and what each one holds.
The stack is defined in docker-compose.prod.yml under the project name wi-prod. The file
ships inside the wi-server image, and install.sh extracts it from the image it pulls, so it
always matches that version.
Containers#
| Service | Image | What it does |
|---|---|---|
postgres |
pgvector/pgvector:pg17 |
The database. Health-checked with pg_isready. Its port is not published. |
app |
ghcr.io/<owner>/wi-server:<tag> |
The application server on internal port 8300. On start it applies database migrations, then serves. It never loads sample data. It mounts the Docker socket so it can run the per-company Coworker workbench containers and the in-app updater. |
dokku |
dokku/dokku:0.35.16 |
The Dokku host for deployed Apps. Its container name is wi-prod-dokku. It publishes WI_DOKKU_SSH_PORT (default 22) for Builders' git push. |
web |
ghcr.io/<owner>/wi-web:<tag> |
Caddy, serving the web app and forwarding /api/*, /auth/*, /healthz, and /apps/serve/*. It publishes ports 80 and 443 and starts after app is healthy and dokku has started. |
<owner> defaults to radialventures and <tag> to latest. See
Configuration reference.
The app container mounts three things:
- the
wi-prod-app-datavolume at/data; - the host's Docker socket;
- the host's Docker config directory (
/root/.dockerby default) read-only, for registry credentials.
Coworker workbench containers and deployed Apps' containers are created on the same Docker daemon at runtime. They are not services in the compose file.
Volumes#
| Volume | Holds | Back it up |
|---|---|---|
wi-prod-data |
Postgres data. | Yes. |
wi-prod-app-data |
Application files at /data: the identity signing key, Coworker workbench home directories, and the pre-update database backups in /data/backups. |
Yes. |
wi-prod-dokku-data |
Dokku's data: deployed Apps' repositories and configuration. | Yes. |
wi-prod-caddy-data |
Caddy's certificates and certificate-authority account. | Keep it. Never delete it. See Domains and HTTPS. |
Together with .env, these volumes are everything that matters on the box. See
Backups and recovery on AWS and
Master key custody.
What the in-app updater replaces#
An in-app update replaces the app and web containers. It does not touch postgres or
dokku, and it does not change the compose file. See
What an update changes and
How an update runs.