Production Configuration

A complete Gordon configuration for production environments.

When to Use

  • Production deployments
  • Multiple applications
  • Services requiring databases

Configuration

# ~/.config/gordon/gordon.toml

# Server settings
[server]
port = 8080                              # Cloudflare forwards 443 → 8080
registry_port = 5000
gordon_domain = "gordon.company.com"

# Authentication with pass backend (recommended)
[auth]
enabled = true
secrets_backend = "pass"
token_secret = "gordon/auth/token_secret"

# File-based logging with rotation
[logging]
level = "info"
format = "json"

[logging.file]
enabled = true
path = "~/.gordon/logs/gordon.log"
max_size = 100
max_backups = 10
max_age = 90

# Workload logs are read from the container runtime with
# `gordon apps logs APP --service SERVICE`.

# Volume settings (all enabled by default)
[volumes]
auto_create = true
prefix = "gordon"
preserve = true

# Network isolation for security
[network_isolation]
enabled = true
network_prefix = "prod"

# Applications, routes, services, and shared networks are declared in
# separate app manifest files and applied with `gordon apps apply`.

Setup Steps

1. Install Pass

sudo apt install pass gnupg
gpg --gen-key
pass init your-gpg-key-id

2. Store Token Secret

# Generate random secret
openssl rand -base64 32 | pass insert -m gordon/auth/token_secret

3. Generate CI Token

gordon auth token generate --subject ci-bot --scopes push,pull --expiry 0

4. Set App Secrets

Declare public values under [env] and secret names under [services.<name>.secrets] in each app file, apply it, then set the values:

gordon apps apply --file ./app.toml
pass show company/db-password \
  | gordon apps secrets set app --service web --stdin --key DATABASE_PASSWORD

5. Configure Cloudflare

Type Name Content Proxy
A app VPS IP Yes
A api VPS IP Yes
A admin VPS IP Yes
A registry VPS IP Yes

6. Start Gordon

systemctl --user enable --now gordon

Features Enabled

Feature Status
Registry Enabled
Token Auth Enabled
File Logging Enabled with rotation
Container Logs Enabled with rotation
Network Isolation Enabled
Attachments Configured
Secrets (pass) Enabled

Deployment Workflow

# Build locally
docker build -t company-app .

# Tag with version
docker tag company-app gordon.company.com/company-app:v2.2.0

# Push to deploy
docker push gordon.company.com/company-app:v2.2.0

# Update config with new version
vim ~/.config/gordon/gordon.toml
# Change: "app.company.com" = "company-app:v2.2.0"

# Reload to deploy
gordon daemon reload