This looks like a great setup by the author, but difficult to maintain in the long run without significant time investment.
This looks like a great setup by the author, but difficult to maintain in the long run without significant time investment.
It was a relief. Coupled with watchtower the updates are automatic except for the two services I really rely upon.
I used to be on Ubuntu for ages and moved to Arch a few days ago - my server only runs docker today.
I still want to keep access to a shell do it is Arch and not Rancher or something (I did not research much the bare metal hypervisors).
My maintenance is minutes every month if everything works fine, up to a max of an hour when Home Assistant broke things once two years ago.
DRP from bare metal is an hour.
Adding a service is a few minutes.
If you then want to put a reverse proxy in front of the docker containers (you almost invariably will), then you can look at different options like caddy, Traefik, nginx etc. I, for one, like to be old-fashioned and have my docker containers' ports bound to localhost, then manually maintain my own "outside of docker" instance of nginx as a reverse proxy that uses these as upstreams. That's not the most "container-first" way of working, but it worked for me. Caddy can do similar. Traefik is more integrated with docker and the docker ecosystem, but that might do what you need better.
docker also adds a big attack surface.
The problem was, at some point Debian stable got so distant from modern infrastructure you had to patch it from the beginning with newer versions, so reluctantly I switched to testing (that was years ago). I was surprised to find out things were working just fine.
The problem is today everybody distributes software in their own way. Especially web software - native packages are more and more rare. So automatic updates that work are indeed a challenge.