Health & OpsDeploy
42 days

Staging Deployment

How the current build is packaged and rolled out onto staging. Uploz ships as a single container — web, worker, and an embedded edge sharing one image and one process tree — that binds a fixed range of host ports (8090 / 8091 / 8095) inside the swarmiq-os isolation boundary. Authored from the deploy config (illustrative project-tracking state, permitted per R1), not a query against a live orchestrator.

Running

Container

3

Ports up

3

Processes up

184 MB

Image size

Deploy target

The one container the whole build ships as, and how it is pinned onto the staging host.

Container
uploz-staging
State
Running
Image
registry.internal/uploz/app:staging-2026.06.08
Image size
184 MB
Host
swarmiq-os / staging-node-1
Restart policy
unless-stopped

Port bindings

The fixed range of host ports the container exposes. 8090/8091 are public surfaces behind the edge; 8095 is internal to swarmiq-os.

Host portSurfaceExposureState

8090 → 3000

http

Web + API

Next.js app and route handlers. The only public surface; everything else sits behind the edge.

PublicRunning

8091 → 3001

ws

Realtime / live updates

WebSocket channel that pushes live job + cockpit updates to connected clients.

PublicRunning

8095 → 9090

http

Health + metrics

Liveness/readiness probes and the Prometheus scrape endpoint. Internal to swarmiq-os only.

InternalRunning

Single-container architecture

Web, worker, and the embedded edge run as processes inside the one image — not as separate services.

webRunning

Next.js server — UI, route handlers, and the write-path RPC callers.

workerRunning

In-process background worker draining the job queue and pushing realtime updates.

edgeRunning

Embedded reverse proxy / TLS terminator fronting the web and realtime surfaces.

swarmiq-os isolation

The staging container runs inside the swarmiq-os boundary: a dedicated namespace on the shared host with its own network, mounts, and port reservations. The fixed 8090 / 8091 / 8095 range is allocated to Uploz alone, so the single container can be scheduled next to other workloads without colliding with them, and the internal health/metrics surface on 8095 is never reachable from outside the boundary.

Illustrative project-tracking state (permitted per R1), authored from the deploy / compose config rather than a live orchestrator query. Service-role keys and other server-only secrets live inside the container and are never exposed on a host port.