But then you have to update the container, and you need a script to do it. Then you need to roll something back, maybe automatically. Maybe you want a load balancer in front of your server to do TLS termination, and at this point you’d benefit from just using k8s (or ecs or google cloud run)
On my home server I use Chef. I have a recipe for each service that sets up a docker container plus an NGINX config that does the TLS and port mapping stuff. To handle container updates I run Watchtower (https://containrrr.dev/watchtower/) which pulls and then restarts my containers when I send a POST.
Deploys are super easy, just docker build, docker push, curl -h $DEPLOY_TOKEN $DEPLOY_URL.
don’t need anything complicated for rollback, just retag and curl again.
It’s a sidestep of complexity IMO.
Then what is? It seems like a lot of the single server ochestration stuff has all been left to rot.