One app, one container, one network

Starting point

One nginx served both sites. A mistake in one configuration could hit both.

Decision

Every application gets its own nginx container. It binds no host port and is reachable only through the internal proxy network.

Implementation

  • The shared nginx becomes nginx-odabas and nginx-waverider.
  • The second domain moved along at the same time, so it no longer needed a separate stage.
  • After the rebuild I checked that nothing except Traefik listens on host ports 80 and 443.

Takeaway

Isolation is the frame in which I can safely try new applications later: whatever goes wrong in one container stays there.