Staging Deployment
How the current build is packaged and rolled out onto staging. Uploz ships as a single container — web, worker, and an embedded edge sharing one image and one process tree — that binds a fixed range of host ports (8090 / 8091 / 8095) inside the swarmiq-os isolation boundary. Authored from the deploy config (illustrative project-tracking state, permitted per R1), not a query against a live orchestrator.
Container
3
Ports up
3
Processes up
184 MB
Image size
Deploy target
The one container the whole build ships as, and how it is pinned onto the staging host.
- Container
- uploz-staging
- State
- Running
- Image
- registry.internal/uploz/app:staging-2026.06.08
- Image size
- 184 MB
- Host
- swarmiq-os / staging-node-1
- Restart policy
- unless-stopped
Port bindings
The fixed range of host ports the container exposes. 8090/8091 are public surfaces behind the edge; 8095 is internal to swarmiq-os.
| Host port | Surface | Exposure | State |
|---|---|---|---|
8090 → 3000 http | Web + API Next.js app and route handlers. The only public surface; everything else sits behind the edge. | Public | Running |
8091 → 3001 ws | Realtime / live updates WebSocket channel that pushes live job + cockpit updates to connected clients. | Public | Running |
8095 → 9090 http | Health + metrics Liveness/readiness probes and the Prometheus scrape endpoint. Internal to swarmiq-os only. | Internal | Running |
Single-container architecture
Web, worker, and the embedded edge run as processes inside the one image — not as separate services.
Next.js server — UI, route handlers, and the write-path RPC callers.
In-process background worker draining the job queue and pushing realtime updates.
Embedded reverse proxy / TLS terminator fronting the web and realtime surfaces.
swarmiq-os isolation
The staging container runs inside the swarmiq-os boundary: a dedicated namespace on the shared host with its own network, mounts, and port reservations. The fixed 8090 / 8091 / 8095 range is allocated to Uploz alone, so the single container can be scheduled next to other workloads without colliding with them, and the internal health/metrics surface on 8095 is never reachable from outside the boundary.
Illustrative project-tracking state (permitted per R1), authored from the deploy / compose config rather than a live orchestrator query. Service-role keys and other server-only secrets live inside the container and are never exposed on a host port.