Servers & OS

What is Docker

What it is

A "box" for a program. Any program needs an environment to run: the right library versions, settings, helper files. Docker packs the program and that whole environment into one box — a container. The box can be moved to any server and will work there exactly as it did with us: nothing needs reinstalling or reconfiguring by hand. Much like a shipping container: any port crane can lift it, no matter what's inside.

Why it matters for business

Moving to another server takes hours, not weeks; one program can't break another on the same server; if something crashes, the container restarts itself. In almost every project the bot, the database and the website live in separate containers. Compose is the "manifest" of all a project's boxes so they start with one command; Swarm spreads them across several servers.

Where Docker helps a business

  • One server runs a website, a bot and a database, and editing one must not take down the rest.
  • The server needs to change, and nobody wants to install and configure everything by hand again.
  • The project goes to another developer or to the client's server and must work exactly as it does for us.
  • A crashed program should come back by itself instead of waiting for the morning and an administrator.

How we use it

Almost every studio project runs in containers, with the set of containers described in docker-compose.

  • Isolated websites. On the websites server every site has its own container and its own Docker network that holds only the site and the entry nginx. Databases are attached only to their own projects' internal networks, so a break-in on one site gives no path to a neighbour's database.
  • A store as one stack. The online store is four containers: database, cache, API and storefront. The database schema is applied by migrations when the API starts.
  • A bot with no open ports. The insurance-policy bot runs in a read-only container with no open ports: it connects to Telegram itself.
  • Data survives a rebuild. In the birthday bot the database file lives on the host's disk, and the container has a 256 MB memory limit and log rotation.
  • Profiles for the job. In the video downloader bot a local Bot API for files up to 2 GB is switched on as a separate docker-compose profile.

Docker deployment is part of our bots, websites and infrastructure work.

Common problems

  • Data inside a container vanishes on rebuild. The database and uploaded files must live in a volume on the host's disk.
  • Server time instead of your time. Without an explicit time zone, reminders, logs and quiet hours follow the hosting provider's clock. We set the time zone in every container.
  • Logs eat the disk. Docker log size is capped, and the entry nginx has its own rotation.
  • The build does not fit in the server's memory. The Nuxt site image is built on a workstation and uploaded ready-made, because the server lacks memory for the build.
  • The container runs but the service is dead. You need a health check, not just a running process: in Peregovorka a watchdog restarts a stuck container, but no more than three times an hour.

When you do not need it

Static pages with no server side do fine without Docker: the VPN setup guides are five HTML files on GitHub Pages, with no build step and no .env. A single script that runs once a day on an office computer does not need a container either.

← All terms

Need a website, a bot or automation?

Terms explained — now let's get to work: tell us about the task and we'll turn it into a clear work plan.