~/wiki

docker deployment

---
title: Docker Deployment
category: concepts
created: 2025-01-04
updated: 2025-01-04
tags: [docker, containerization, deployment, infrastructure, openclaw, per-client-deployment, isolation, orchestration, docker-compose, production-deployment, container-management, resource-limits, security-isolation, scalability, microservices]
sources: [raw/conversations/2026-03-27-cursor-openclaws-6ddf77d1.md]
confidence: high
---

# Docker Deployment

Containerization-based deployment strategy providing process isolation, resource management, and simplified application packaging. Particularly valuable for [per-client-deployment-pattern](/concepts/per-client-deployment-pattern) and openclaw implementations requiring secure multi-tenant environments.

## Core Benefits

### Process Isolation
- **Contained execution**: Applications run in isolated namespaces
- **Resource boundaries**: CPU, memory, and I/O limits per container
- **Security isolation**: Processes cannot access host or other containers
- **Dependency management**: Each container includes all required dependencies

### Deployment Consistency
- **Environment parity**: Identical execution across development, staging, production
- **Version control**: Immutable image tags for reproducible deployments
- **Rollback capability**: Quick reversion to previous working versions
- **Configuration management**: Environment variables and mounted configurations

## Implementation Patterns

### Single Application Deployment

#### Basic Docker Configuration
```dockerfile
FROM node:18-alpine
WORKDIR /app
COPY package*.json ./
RUN npm ci --only=production
COPY . .
EXPOSE 3000
CMD ["npm", "start"]

Environment Configuration

# docker-compose.yml
version: '3.8'
services:
  app:
    build: .
    ports:
      - "3000:3000"
    environment:
      - NODE_ENV=production
      - DATABASE_URL=${DATABASE_URL}
    volumes:
      - ./data:/app/data

Multi-Client Architecture

Per-Client Container Strategy

For client-facing-ai-development scenarios:

# client1-compose.yml
version: '3.8'
services:
  openclaw-client1:
    image: openclaw:latest
    container_name: openclaw_client1
    environment:
      - CLIENT_ID=client1
      - WORKSPACE_PATH=/workspace
      - TELEGRAM_BOT_TOKEN=${CLIENT1_BOT_TOKEN}
      - CLAUDE_API_KEY=${CLAUDE_API_KEY}
    volumes:
      - ./clients/client1:/workspace:rw
      - ./configs/client1.yml:/app/config.yml:ro
    networks:
      - client1_network
    restart: unless-stopped
    deploy:
      resources:
        limits:
          memory: 512M
          cpus: '0.5'

Orchestration Scripts

#!/bin/bash
# deploy-client.sh
CLIENT_ID=$1
BOT_TOKEN=$2

# Create client directory structure
mkdir -p ./clients/${CLIENT_ID}
mkdir -p ./configs/

# Generate client-specific configuration
envsubst < templates/client-config.yml > configs/${CLIENT_ID}.yml

# Deploy container
docker-compose -f ${CLIENT_ID}-compose.yml up -d

echo "Client ${CLIENT_ID} deployed successfully"

Resource Management

Memory and CPU Limits

deploy:
  resources:
    limits:
      memory: 1G
      cpus: '1.0'
    reservations:
      memory: 512M
      cpus: '0.5'

Storage Management

volumes:
  - type: bind
    source: ./client-data
    target: /app/data
    read_only: false
  - type: bind
    source: ./client-config
    target: /app/config
    read_only: true

Security Considerations

Container Hardening

Non-Root Execution

# Create non-root user
RUN addgroup -g 1001 -S appgroup && \
    adduser -S appuser -G appgroup -u 1001

# Set ownership
CHOWN appuser:appgroup /app

# Switch to non-root user
USER appuser

Minimal Base Images

# Use distroless or Alpine images
FROM gcr.io/distroless/nodejs:18
# or
FROM node:18-alpine

Security Scanning

# Scan image for vulnerabilities
docker scan openclaw:latest

# Use security-focused base images
FROM chainguard/node:latest

Network Security

Custom Networks

networks:
  client_network:
    driver: bridge
    internal: true  # No external internet access
  
  shared_services:
    driver: bridge
    external: true

Port Management

services:
  app:
    ports:
      - "127.0.0.1:3000:3000"  # Bind to localhost only
    expose:
      - "3000"  # Internal container communication

Production Deployment

Health Checks

services:
  app:
    healthcheck:
      test: ["CMD", "curl", "-f", "http://localhost:3000/health"]
      interval: 30s
      timeout: 10s
      retries: 3
      start_period: 40s

Logging Configuration

services:
  app:
    logging:
      driver: "json-file"
      options:
        max-size: "10m"
        max-file: "3"

Restart Policies

services:
  app:
    restart: unless-stopped  # Restart unless explicitly stopped
    # or
    restart: on-failure:3    # Restart on failure, max 3 attempts

Monitoring and Observability

Container Metrics

# Monitor resource usage
docker stats

# View container logs
docker logs -f container_name

# Inspect container details
docker inspect container_name

Integration with Monitoring Systems

# Prometheus monitoring
services:
  app:
    labels:
      - "prometheus.io/scrape=true"
      - "prometheus.io/port=3000"
      - "prometheus.io/path=/metrics"

Scaling Patterns

Horizontal Scaling

# Docker Swarm scaling
docker service scale app=3

# Or manual replica management
services:
  app:
    deploy:
      replicas: 3

Load Balancing

# Nginx load balancer
services:
  nginx:
    image: nginx:alpine
    ports:
      - "80:80"
    depends_on:
      - app
    volumes:
      - ./nginx.conf:/etc/nginx/nginx.conf

Operational Workflows

CI