<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Docker on Ownchain Systems</title>
    <link>https://ownchain.systems/tags/docker/</link>
    <description>Recent content in Docker on Ownchain Systems</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sun, 30 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://ownchain.systems/tags/docker/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>CODEX-001: Decommissioning Socket-Mounted Web UIs &amp; Enforcing Terminal-Native Ops</title>
      <link>https://ownchain.systems/codex/001-socket-hardening/</link>
      <pubDate>Sun, 30 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://ownchain.systems/codex/001-socket-hardening/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; Ingress Hardening &amp;amp; Attack Surface Reduction&lt;br&gt;&#xA;&lt;strong&gt;Status:&lt;/strong&gt; Implemented &amp;amp; Verified&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;executive-summary&#34;&gt;Executive Summary&lt;/h2&gt;&#xA;&lt;p&gt;This report documents the architectural lifecycle of container management on Bastion: from initially deploying a web-based GUI (Portainer) to overcome early CLI friction, to identifying the inherent security risks of host-socket mounting, and finally decommissioning the interface in favor of key-authenticated, terminal-native tooling (&lt;code&gt;lazydocker&lt;/code&gt;).&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;phase-1-initial-deployment--context&#34;&gt;Phase 1: Initial Deployment &amp;amp; Context&lt;/h2&gt;&#xA;&lt;h3 id=&#34;why-portainer-was-introduced&#34;&gt;Why Portainer Was Introduced&lt;/h3&gt;&#xA;&lt;p&gt;When initially transitioning to Docker and container orchestration, early CLI management presented significant friction. Debugging multi-container networks, diagnosing container start failures, and managing persistent volume paths purely through raw shell commands often led to silent errors and operational overhead.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CODEX-003: Container Lifecycle, Layer Drift &amp; Database Migrations</title>
      <link>https://ownchain.systems/codex/003-container-lifecycle/</link>
      <pubDate>Sun, 30 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://ownchain.systems/codex/003-container-lifecycle/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Classification:&lt;/strong&gt; Operational Lifecycle &amp;amp; Database Resilience&lt;br&gt;&#xA;&lt;strong&gt;Status:&lt;/strong&gt; Implemented &amp;amp; Verified&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;executive-summary&#34;&gt;Executive Summary&lt;/h2&gt;&#xA;&lt;p&gt;This report documents the failure modes, triage, and safe maintenance patterns discovered while updating multi-container microservice stacks with tightly coupled database dependencies. It analyzes race conditions during parallel image layer pulls, container recreations vs. image caching, and ensuring zero data loss during automated backend schema migrations.&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;h2 id=&#34;the-problem-statement--failure-modes&#34;&gt;The Problem Statement &amp;amp; Failure Modes&lt;/h2&gt;&#xA;&lt;p&gt;Updating production-grade container stacks (such as Firefly III, its importer, cron sidecar, and MariaDB/MySQL backend) presents subtle operational risks if treated like simple stateless containers:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
