# Production deployment files The DTF application is one Portainer-owned Docker Swarm stack. Gitea builds, tests, scans, and publishes the two application images, then calls the stack's Portainer webhook. Start with the short operator guide in `../PORTAINER.md`. - `stack.yaml` — the single Portainer stack. - `Dockerfile.api` and `Dockerfile.web` — prebuilt registry images. - `portainer.env.example` — non-secret Portainer variables. - `production_preflight.py` — fail-closed application/configuration validator. - `PRODUCTION_CHECKLIST.md` — production evidence checklist. The current application remains deliberately blocked from production because real adapters and Docker-secret file loading are absent and current validation base images have unresolved HIGH/CRITICAL findings. No real provider or production service has been configured or contacted.