Containers and volumes

The containers and Docker volumes that make up a Workforce Intelligence deployment, and what each one holds.

For: Administrators operating a deployment · Last updated

The stack is defined in docker-compose.prod.yml under the project name wi-prod. The file ships inside the wi-server image, and install.sh extracts it from the image it pulls, so it always matches that version.

Containers#

Service Image What it does
postgres pgvector/pgvector:pg17 The database. Health-checked with pg_isready. Its port is not published.
app ghcr.io/<owner>/wi-server:<tag> The application server on internal port 8300. On start it applies database migrations, then serves. It never loads sample data. It mounts the Docker socket so it can run the per-company Coworker workbench containers and the in-app updater.
dokku dokku/dokku:0.35.16 The Dokku host for deployed Apps. Its container name is wi-prod-dokku. It publishes WI_DOKKU_SSH_PORT (default 22) for Builders' git push.
web ghcr.io/<owner>/wi-web:<tag> Caddy, serving the web app and forwarding /api/*, /auth/*, /healthz, and /apps/serve/*. It publishes ports 80 and 443 and starts after app is healthy and dokku has started.

<owner> defaults to radialventures and <tag> to latest. See Configuration reference.

The app container mounts three things:

  • the wi-prod-app-data volume at /data;
  • the host's Docker socket;
  • the host's Docker config directory (/root/.docker by default) read-only, for registry credentials.

Coworker workbench containers and deployed Apps' containers are created on the same Docker daemon at runtime. They are not services in the compose file.

Volumes#

Volume Holds Back it up
wi-prod-data Postgres data. Yes.
wi-prod-app-data Application files at /data: the identity signing key, Coworker workbench home directories, and the pre-update database backups in /data/backups. Yes.
wi-prod-dokku-data Dokku's data: deployed Apps' repositories and configuration. Yes.
wi-prod-caddy-data Caddy's certificates and certificate-authority account. Keep it. Never delete it. See Domains and HTTPS.

Together with .env, these volumes are everything that matters on the box. See Backups and recovery on AWS and Master key custody.

What the in-app updater replaces#

An in-app update replaces the app and web containers. It does not touch postgres or dokku, and it does not change the compose file. See What an update changes and How an update runs.