Day-two operations
Check status, stop, start, restart, and pull images on a running deployment with Docker Compose.
Everything runs under the Docker Compose project name wi-prod. Every service has the
restart policy unless-stopped, so a full reboot of the box recovers on its own. You do not
need to run anything after a reboot.
.env sits next to docker-compose.prod.yml (/opt/wi on the AWS path), and Compose reads it
automatically. You never type environment variables on a command line.
Commands#
Commands that act on running containers find them by the project name, so they work from any directory:
sudo docker compose -p wi-prod ps # what is running
sudo docker compose -p wi-prod logs app # the application's log
sudo docker compose -p wi-prod stop # stop everything; data volumes are untouched
sudo docker compose -p wi-prod start # start everything again
sudo docker compose -p wi-prod restart app # restart one service
Commands that read the configuration need the compose file, so run them from the directory that holds it and name the file:
cd /opt/wi
sudo docker compose -f docker-compose.prod.yml up -d # recreate anything whose settings changed
Run up -d after you edit .env. It recreates the containers whose configuration changed.
To move to a newer release, use Settings → Updates: it backs up the database first and
switches over only after the new version is healthy. See
Checking for and installing updates. When a
release changes the stack itself, re-run install.sh first. See
What an update changes. Do not pull images by hand with
docker compose pull: that skips the backup and the health check.
The registry login#
GHCR_USER and GHCR_TOKEN are needed only while the box is not logged in to ghcr.io.
install.sh runs the docker login, Docker stores it, and every later pull and re-run of
install.sh uses it. If the token expires
or is revoked, log in again with a fresh classic token, always with sudo, and restart the app.
See Registry credentials for updates.
Read the application log#
sudo docker compose -p wi-prod logs --tail 200 app
Logs are JSON lines on standard output, so Docker's own log driver holds them.
Health#
The application answers /healthz on its internal port 8300, and the app container's health
check calls it. sudo docker compose -p wi-prod ps shows each container's state and health.