docker deployment
---
title: Docker Deployment
category: concepts
created: 2025-01-04
updated: 2025-01-04
tags: [docker, containerization, deployment, infrastructure, openclaw, per-client-deployment, isolation, orchestration, docker-compose, production-deployment, container-management, resource-limits, security-isolation, scalability, microservices]
sources: [raw/conversations/2026-03-27-cursor-openclaws-6ddf77d1.md]
confidence: high
---
# Docker Deployment
Containerization-based deployment strategy providing process isolation, resource management, and simplified application packaging. Particularly valuable for [per-client-deployment-pattern](/concepts/per-client-deployment-pattern) and openclaw implementations requiring secure multi-tenant environments.
## Core Benefits
### Process Isolation
- **Contained execution**: Applications run in isolated namespaces
- **Resource boundaries**: CPU, memory, and I/O limits per container
- **Security isolation**: Processes cannot access host or other containers
- **Dependency management**: Each container includes all required dependencies
### Deployment Consistency
- **Environment parity**: Identical execution across development, staging, production
- **Version control**: Immutable image tags for reproducible deployments
- **Rollback capability**: Quick reversion to previous working versions
- **Configuration management**: Environment variables and mounted configurations
## Implementation Patterns
### Single Application Deployment
#### Basic Docker Configuration
```dockerfile
FROM node:18-alpine
WORKDIR /app
COPY package*.json ./
RUN npm ci --only=production
COPY . .
EXPOSE 3000
CMD ["npm", "start"]
Environment Configuration
# docker-compose.yml
version: '3.8'
services:
app:
build: .
ports:
- "3000:3000"
environment:
- NODE_ENV=production
- DATABASE_URL=${DATABASE_URL}
volumes:
- ./data:/app/data
Multi-Client Architecture
Per-Client Container Strategy
For client-facing-ai-development scenarios:
# client1-compose.yml
version: '3.8'
services:
openclaw-client1:
image: openclaw:latest
container_name: openclaw_client1
environment:
- CLIENT_ID=client1
- WORKSPACE_PATH=/workspace
- TELEGRAM_BOT_TOKEN=${CLIENT1_BOT_TOKEN}
- CLAUDE_API_KEY=${CLAUDE_API_KEY}
volumes:
- ./clients/client1:/workspace:rw
- ./configs/client1.yml:/app/config.yml:ro
networks:
- client1_network
restart: unless-stopped
deploy:
resources:
limits:
memory: 512M
cpus: '0.5'
Orchestration Scripts
#!/bin/bash
# deploy-client.sh
CLIENT_ID=$1
BOT_TOKEN=$2
# Create client directory structure
mkdir -p ./clients/${CLIENT_ID}
mkdir -p ./configs/
# Generate client-specific configuration
envsubst < templates/client-config.yml > configs/${CLIENT_ID}.yml
# Deploy container
docker-compose -f ${CLIENT_ID}-compose.yml up -d
echo "Client ${CLIENT_ID} deployed successfully"
Resource Management
Memory and CPU Limits
deploy:
resources:
limits:
memory: 1G
cpus: '1.0'
reservations:
memory: 512M
cpus: '0.5'
Storage Management
volumes:
- type: bind
source: ./client-data
target: /app/data
read_only: false
- type: bind
source: ./client-config
target: /app/config
read_only: true
Security Considerations
Container Hardening
Non-Root Execution
# Create non-root user
RUN addgroup -g 1001 -S appgroup && \
adduser -S appuser -G appgroup -u 1001
# Set ownership
CHOWN appuser:appgroup /app
# Switch to non-root user
USER appuser
Minimal Base Images
# Use distroless or Alpine images
FROM gcr.io/distroless/nodejs:18
# or
FROM node:18-alpine
Security Scanning
# Scan image for vulnerabilities
docker scan openclaw:latest
# Use security-focused base images
FROM chainguard/node:latest
Network Security
Custom Networks
networks:
client_network:
driver: bridge
internal: true # No external internet access
shared_services:
driver: bridge
external: true
Port Management
services:
app:
ports:
- "127.0.0.1:3000:3000" # Bind to localhost only
expose:
- "3000" # Internal container communication
Production Deployment
Health Checks
services:
app:
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:3000/health"]
interval: 30s
timeout: 10s
retries: 3
start_period: 40s
Logging Configuration
services:
app:
logging:
driver: "json-file"
options:
max-size: "10m"
max-file: "3"
Restart Policies
services:
app:
restart: unless-stopped # Restart unless explicitly stopped
# or
restart: on-failure:3 # Restart on failure, max 3 attempts
Monitoring and Observability
Container Metrics
# Monitor resource usage
docker stats
# View container logs
docker logs -f container_name
# Inspect container details
docker inspect container_name
Integration with Monitoring Systems
# Prometheus monitoring
services:
app:
labels:
- "prometheus.io/scrape=true"
- "prometheus.io/port=3000"
- "prometheus.io/path=/metrics"
Scaling Patterns
Horizontal Scaling
# Docker Swarm scaling
docker service scale app=3
# Or manual replica management
services:
app:
deploy:
replicas: 3
Load Balancing
# Nginx load balancer
services:
nginx:
image: nginx:alpine
ports:
- "80:80"
depends_on:
- app
volumes:
- ./nginx.conf:/etc/nginx/nginx.conf