docs: name the stack Portainer actually deploys, and its credential exposure

PORTAINER.md called deploy/stack.yaml the production stack. The deployed file is
docker-compose.yml, which supplies eight credentials as plain environment
variables where stack.yaml uses Docker secrets. That puts the database password,
operator password and the R2 secret key in the container environment, readable
through docker inspect and the Portainer stack editor.

Recorded as ROADMAP 2.12 with the three options rather than changed here:
altering how production receives credentials is not a quiet change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-21 13:42:12 -03:00
parent c1a07a75fa
commit e95a42dbed
2 changed files with 40 additions and 1 deletions

View File

@@ -4,7 +4,13 @@ DTF follows the same operating model as Graphs and ComporHUB: Gitea builds
prebuilt images, pushes them to the Gitea registry, and calls one Portainer
webhook. Portainer owns and redeploys one Docker Swarm stack named `dtf-cloud`.
The production stack is `deploy/stack.yaml`. It contains Site, Kanban, API,
The deployed stack is the repository's `docker-compose.yml`, which the
`dtf-cloud` Portainer stack points at. `deploy/stack.yaml` is a more hardened
definition that supplies every credential as a Docker secret rather than an
environment variable; it is not currently deployed. See `ROADMAP.md` 2.12 before
assuming either is authoritative.
`deploy/stack.yaml` contains Site, Kanban, API,
worker, PostgreSQL, ClamAV, and a one-time database initializer. Production uses
Cloudflare R2, so MinIO is not part of this stack.