One app, one container, one network
Starting point
One nginx served both sites. A mistake in one configuration could hit both.
Decision
Every application gets its own nginx container. It binds no host port and is reachable only through the internal proxy network.
Implementation
- The shared nginx becomes
nginx-odabasandnginx-waverider. - The second domain moved along at the same time, so it no longer needed a separate stage.
- After the rebuild I checked that nothing except Traefik listens on host ports 80 and 443.
Takeaway
Isolation is the frame in which I can safely try new applications later: whatever goes wrong in one container stays there.