Take stock instead of starting over
Starting point
My VPS ran two WordPress sites behind a shared nginx. The server had grown over months, and the Compose file no longer matched what was actually running.
The trigger was an outage: a Git commit had moved nginx configuration files, and the certificates had silently been expired for five months.
This is what it looked like before the migration.
Decision
Before I change anything, I want to know what is really running. I reconstruct the current state from the running containers and make it the foundation in the Git repository.
Implementation
docker inspectgives me images, networks, volumes and environment variables of every container.- From that I build a new
docker-compose.ymland check it against the live system. - The nginx configuration, the Let’s Encrypt renewal and a mail alert via
msmtpare repaired, plus a kernel update.
Takeaway
Infrastructure as code starts with an honest inventory. A Compose file that does not match the live system is worse than none at all.