mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-26 11:49:16 +00:00
9ff678a7bb
* docs(introduction): refresh for the redesigned UI and replace screenshots Bring the Getting Started Introduction page in line with the current product: - Add the Security top-level view to the navigation list and a dedicated Security section with a new screenshot. - Correct the Fleet tab names (Snapshots, Status, Map, Deployments, Routing, Federation, Actions, Secrets). - Split Settings out from security and list the current nine setting groups (Security graduated to its own view). - Refine the navigation paragraph so role, tier, and local-vs-remote context read accurately. Replace all four existing screenshots (Home, stack workspace, Fleet, Resources) with fresh captures of the redesigned UI and add a Security overview screenshot. * docs(configuration): document advanced env vars and clarify deployment vs runtime config Add an Advanced environment variables section (TRIVY_BIN, SENCHO_MESH_SUBNET, GITSOURCE_MAX_CLONE_BYTES, SENCHO_PUBLIC_URL, SENCHO_COMPOSE_STALL_TIMEOUT_MS) and reframe the intro to separate deployment-time configuration from the runtime settings that live in the in-app Settings Hub. Cross-link the pilot-agent variables to the Pilot Agent page instead of duplicating them. * docs(sso): refresh SSO Setup Guide and SSO & LDAP reference for the redesigned UI Refresh both SSO documentation pages against the current product and the redesigned settings UI. - Correct the navigation path to Settings -> Access -> SSO on both pages. - Fix the "Require 2FA on SSO sign-in" toggle location to Settings -> Personal -> Account. - Describe the login-page experience (the Local / LDAP toggle and the branded OIDC buttons under the "Or continue with" divider) and the SSO panel masthead (SCOPE, PROVIDERS, ENABLED). - Replace all six SSO screenshots with fresh captures of the redesigned UI. * docs(features): refresh the Features Overview page for the redesigned UI Rewrite docs/features/overview.mdx to mirror the current Features navigation grouping (Stacks, Deployment, Resources, Observability, Fleet, Automation, Security & Identity) and add the recently shipped capabilities surfaced in the redesign: Stack Dossier, Drift Detection, Compose Doctor, Compose Networking, Environment & secrets guardrails, Storage portability, Health-Gated Updates, Fleet Dossier, and the dedicated Security page. Correct stale claims (the file explorer now gates writes on stack edit permission, not an admin role; downloads are a read action; bulk label assign now spans nodes) and standardize the tier callouts so partly paid features read as "Admiral adds X". Replace the three pre-redesign screenshots and add a Security overview banner, all captured from a populated fleet. * docs(features): refresh the Appearance page for the redesigned UI Add fresh screenshots and a troubleshooting section to the Appearance page, verified against the live product. - Add four screenshots: the Theme card (live preview, mode, accent, and fine-tune sliders), the top-bar quick switcher, the Typography card, and the Display card. - Refresh the Density screenshot used by the Settings reference page. - State that the quick switcher also covers text size, and that the contrast, border, and glow sliders stay in Settings. - Add a Troubleshooting accordion covering per-browser persistence, resets to defaults, cross-operator scope, and the quick-switcher versus full-Settings split. * docs(introduction): refresh screenshots and correct stale content * docs(reference): refresh the Settings Reference page for the redesigned UI Replace all seven stale screenshots with fresh 1920x1080 captures. Add five new screenshots for the sections that previously had none. Content changes: - Sidebar table: rename Infrastructure "Fleet Mesh" entry to "Fleet"; add "Image update checks" to the Automation group list - Fleet section: rename heading to match registry label; add the Documentation snapshots subsection (snapshot_documentation toggle) - Container Alerts: add screenshot - Image update checks: add the full section (Registry checks table, scheduling mode, interval presets, cron expression support) - Stacks / Deploy Guardrails: add screenshot - Recovery: add the full section (System health snapshot, Environment preflight checks, Safe actions, Command-line recovery table) * docs(sso): refresh screenshots for SSO quickstart and feature pages * docs: refresh Features Overview screenshots and content Replace all 4 hero screenshots with fresh 1920x1080 production captures. Correct security posture state names (Action needed / Monitoring / Secure), add the Policies tab to the Security section tab list, mention the Simple mode in Scheduled operations, and update all alt text to match the new screenshots. * docs: refresh Appearance page screenshots and correct quick-switcher scope Replace all four Appearance screenshots with fresh production captures. Fix the quick-switcher control list: remove fonts (not present in the popover), add visual style and readability which are. Add Log chip color to the Display section. Update all screenshot alt text to match new captures. * docs: refresh stack management page with current UI and anatomy tabs * docs: fix convert-tab-error screenshot with fully visible error toast * docs: convert troubleshooting section to AccordionGroup format * docs(quickstart): refresh screenshots and align dashboard description Replace all three first-boot and dashboard screenshots with current UI. Add Security to the top navigation list, update gauge and Stack health descriptions to reflect sparklines and column detail, and align Configuration Status wording with the Introduction page. * docs(editor): rewrite anatomy panel, replace all screenshots - Correct the anatomy panel tab inventory: the panel has eight tabs (Anatomy, Activity, Dossier, Drift always; Environment, Networking, Doctor, Storage when the node advertises the matching capability), not three as previously documented - Add table describing all eight tabs with capability gates and links to dedicated feature pages - Add anatomy-tabs.png screenshot showing the scrollable tab row - Note the Doctor severity dot (red for blocker, amber for high-risk) - Remove the stale Markdown-export subsection; Dossier and Activity are now covered in the tab table - Replace all six stale screenshots with fresh 1920x1080 captures - Replace the compose diff preview screenshot * docs(files): refresh Files & Volumes screenshots and fix context-menu alt text Replace all 9 stale screenshots on the Files & Volumes page with fresh captures from the production node. Fix three alt-text strings that did not match the live UI: removed hardcoded octal value 644, and added the Duplicate, Copy to, and Move to entries missing from the context-menu alt text. * docs: rewrite Stack Activity page with full event categories and fresh screenshots Expands the event category table from 5 to 10 entries to cover drift detected, drift resolved, update started, health gate passed, and health gate failed. Adds a live-disconnected-state section, a background-actor attribution table, and a corrected troubleshooting accordion covering the WebSocket reconnect case. Replaces both stale screenshots with fresh 1920x1080 captures from the production node. * docs(drift): rewrite drift detection page with screenshots and full coverage Full rewrite of the Drift Detection feature page. Adds two previously undocumented finding types (network-undeclared, network-missing), expands the temporal section to distinguish the raw-file hash from the parsed-model hash, documents the two-layer spatial-engine and ledger architecture, explains when the ledger is reconciled (post-deploy vs manual re-check vs tab open), adds Activity timeline integration note, introduces a Limitations section (no background scanner, port-range caveat, history cap, advisory-only enforcement), expands Troubleshooting from five entries to seven using the AccordionGroup convention, and adds four production screenshots. * docs(drift): use CardGroup for Related section * docs(dossier): rewrite Stack Dossier page with full feature coverage * docs(networking): rewrite Compose Networking page with full feature coverage * docs(doctor): rewrite Compose Doctor with full 30-rule reference, screenshots, and cross-links * docs(networking): add production screenshots and correct alt text Adds 7 production screenshots for all sections of the Compose Networking page and updates the four placeholder alt texts written before screenshots were taken to match what the actual images show (arr-net external badge, swag service with 443/tcp and 80/tcp, single-service exposure intent row). Also adds the full-panel overview image at the top of the page. * docs(environment-guardrails): rewrite with project env file, env file status, and screenshots * docs(storage): rewrite Storage Portability page with screenshots and full coverage Rewrites compose-storage.mdx from a 61-line sketch into a complete reference page. Key additions: Where to find it section with screenshot, full storage inventory section documenting all mount type/access/status chips and the Linux owner display, expanded portability verdict section with per-reason detail and edge-case caveats (read-only binds, symlink escapes, anonymous volume risks), snapshot coverage section with admin scope and remote-node behavior, Findings in Doctor cross-reference, and six troubleshooting accordions covering tab visibility, bind status, external named volumes, render errors, and snapshot coverage states. Adds two production screenshots: storage-tab.png and storage-node-bound.png. * docs(stack-labels): rewrite with accurate permissions, capability gate, dry run, live preview, and color conflict docs * docs: rewrite Stack Sidebar page with accurate feature coverage Rewrites the Stack Sidebar documentation page to match the current UI. Key changes: - Fix branding header description (shows logo + version, not just version) - Fix bulk mode icon description (stacked-rows, not square) - Add cross-node search section (fan-out behavior, Other nodes section, unreachable-node warnings, click-to-switch navigation) - Update Labels submenu description (inline New label creation, Manage labels link) - Note that Delete only appears when the user has delete permission - Remove the auto-update implication from Schedule task description - Rewrite the Activity ticker section with the full 6-state priority cascade table; remove the non-existent IDLE state; correct pulsing-dot behavior - Replace all 7 stale screenshots with fresh production screenshots - Add new sidebar-cross-node-search.png screenshot * docs(atomic-deployments): refresh screenshot and document project env files, rollback readiness, and recovery actions * docs(atomic-deployments): fix rollback permission visibility and banner string accuracy The Rollback menu entry is hidden by the frontend when the user lacks stack:deploy; it never appears and does not 403. Fixed the step-4 narrative and troubleshooting accordion to match. The rollback-failure banner emitted by ComposeService is '=== Rollback failed. Manual intervention may be required ===' (period, capital M). Fixed both occurrences in the page. Updated the Settings navigation path from the nonexistent 'Roles & Access' to the real 'Access'. * docs(deploy-progress): rewrite with health gate, inline style, and 9 fresh screenshots Add health gate section covering all four states (observing, passed, failed, unknown) with exact UI banner text and the configurable observation window. Expand the inline style section with full band content, 4s auto-dismiss, and pill handoff. Add Scanning as a supported entry point. Replace all 6 existing screenshots and add 3 new ones (modal-health-gate, inline-banner, setting-style). Add two health gate troubleshooting accordions. Add Related CardGroup linking to health-gated-updates, stack-activity, deploy-enforcement, and atomic-deployments. * docs(health-gated-updates): refresh screenshots and correct signal row order and label * docs(deploy-enforcement): rewrite with fleet replication, honor suppressions location, scan-failed dialog state, and fresh screenshots Adds the Fleet policy replication section covering control/replica behavior, Managed by control node banner, and Demote to control. Documents the exact location of the Honor suppressions toggle (bottom of Policies tab). Expands the block dialog section with the scan-failed row state. Updates all three screenshots to the current visual design. Restores the Admiral license note and corrects the policy-card scope description. * docs(app-store): rewrite with mobile layout, fresh screenshots, and registry admin note - Replace all 5 stale screenshots with 1920x1080 production captures - Add app-store-mobile.png showing the status masthead layout - Document mobile single-column layout in a new Mobile subsection - Note that the featured hero has its own Deploy button - Mark the category rail as desktop only with a cross-link to Mobile - Add admin-account requirement to the custom registry section - Add Related CardGroup linking vulnerability scanning, deploy progress, deploy enforcement, and resources
250 lines
18 KiB
Plaintext
250 lines
18 KiB
Plaintext
---
|
|
title: Compose Networking
|
|
description: Inspect how a stack is connected and exposed, classify its intended exposure, and see where the running containers disagree with the Compose file, all without opening a terminal.
|
|
---
|
|
|
|
The **Networking** tab in the right-hand **Anatomy** panel answers two questions about any stack: *how is it networked and exposed according to the Compose file*, and *does what is actually running agree with that?* It renders the effective Compose model (the fully resolved result after interpolation, includes, profiles, `.env`, and `env_file` are applied), pairs it with a live Docker snapshot when the node is reachable, and presents both as plain, scannable facts.
|
|
|
|
The tab is read-only with respect to stack deployments: it never alters a container, a Compose file, or an existing network attachment. Two write operations are available: setting the stack's *exposure intent* (stored separately so Sencho can flag mismatches over time) and creating a new Docker network on the active node, which is available to admins and covered in [Creating networks](#creating-networks) below.
|
|
|
|
Compose Networking reads structure: network names, service-to-network membership, published ports, network modes, and the *names* of environment variables and labels, never their values. A secret injected through `environment:` or `env_file:` never appears in the view or the logs. One caveat: a structural field assembled by interpolating a secret (a network `name:`, a published port, or an `extra_hosts` entry built from `${VAR}`) is resolved before the inspector reads it, so its value does show. Keep secrets in `environment:` or `env_file:` rather than interpolating them into structural fields. See [Environment and Secrets Guardrails](/features/environment-guardrails).
|
|
|
|
<img
|
|
src="/images/compose-networking/networking-tab-overview.png"
|
|
alt="The Networking tab showing the full panel: EXPOSURE INTENT section with REVERSE-PROXY selected for the stack and INHERIT for the service, NETWORKS section listing arr-net with an external badge, SERVICES section showing swag with ports 443/tcp and 80/tcp both marked 'all interfaces', and RUNTIME DRIFT section showing the green 'runtime matches compose' card"
|
|
/>
|
|
|
|
## Accessing the Networking tab
|
|
|
|
1. Click any stack in the left sidebar to open it.
|
|
2. Switch to the **Networking** tab in the Anatomy panel header.
|
|
|
|
On a phone, the same information appears under the **Compose** section of the stack detail.
|
|
|
|
The tab appears only when the active node reports that it supports Compose Networking. A node running an older version of Sencho hides the tab until it is updated.
|
|
|
|
<Frame>
|
|
<img
|
|
src="/images/compose-networking/networking-tab-location.png"
|
|
alt="The Anatomy panel tab strip showing ANATOMY, ACTIVITY, DOSSIER, DRIFT, ENVIRONMENT, NETWORKING (active and underlined), DOCTOR, STORAGE tabs alongside FILES and EDIT action buttons"
|
|
/>
|
|
</Frame>
|
|
|
|
## Effective model rendering
|
|
|
|
When you open the tab, Sencho runs `docker compose config` on the active node to produce the effective model: the Compose file with all variable substitutions resolved, any `include:` and `extends:` directives merged, profiles filtered, and `.env` and `env_file` values applied. The networking facts you see always reflect this resolved model, not the raw file text.
|
|
|
|
**Network name resolution** follows Compose rules:
|
|
|
|
- By default, Docker names a network `<project>_<key>`, where `project` is the Compose project name (the `name:` field in the file, or the stack's directory name if absent) and `key` is the network's Compose key.
|
|
- If the network block declares its own `name:` field, that exact name is used instead of the `<project>_<key>` default.
|
|
- External networks use the Compose key directly (or the `name:` field if set), because they are expected to already exist on the host rather than being created by the stack.
|
|
|
|
When the Compose key and the resolved Docker name differ, the tab shows both: the Docker name in full text and the key in parentheses beside it.
|
|
|
|
If `docker compose config` cannot produce a model (usually a YAML error, an unresolved variable, or a broken `include`), the tab shows the error message and cannot display any facts. Fix the Compose file and reopen the tab to continue.
|
|
|
|
## Exposure intent
|
|
|
|
<Frame>
|
|
<img
|
|
src="/images/compose-networking/networking-exposure-intent.png"
|
|
alt="The exposure intent section showing a stack row with REVERSE-PROXY highlighted, and one service row (swag) with INHERIT highlighted and an arrow indicator reading 'reverse-proxy', showing the intent inherited from the stack"
|
|
/>
|
|
</Frame>
|
|
|
|
Exposure intent is how you tell Sencho what a stack *should* be reachable from, so it can warn you when the runtime says otherwise. Set one intent for the whole stack, or override it per service when individual services have different exposure profiles.
|
|
|
|
| Intent | Meaning |
|
|
|--------|---------|
|
|
| **internal** | Not reachable from the host at all. Containers communicate only within Docker networks. |
|
|
| **same-node** | Reachable only from the host itself, through loopback-bound ports. |
|
|
| **lan** | Published for the local network. |
|
|
| **reverse-proxy** | Reached through a reverse proxy; no direct host port exposure expected. |
|
|
| **public** | Intentionally reachable from the internet. |
|
|
| **temporary** | A short-lived exposure (a label for tracking only, not a functional configuration). |
|
|
| **unknown** | Not yet classified. |
|
|
|
|
**How inheritance works:** a service with no intent of its own inherits the stack's. In the per-service row, the **inherit** pill is selected when no override is set; an arrow indicator shows the intent the service inherits from the stack. Clearing a service's override returns it to **inherit**. Clearing the stack's intent returns it to unclassified.
|
|
|
|
**Permissions:** editing the intent requires stack edit access. With read-only access you can see the current classification but not change it.
|
|
|
|
**How Doctor uses it:** Sencho stores the intent separately from the computed networking facts. When the two drift apart (a service classified `internal` that is publishing a host port, for example), the **Doctor** tab flags the mismatch. See [Compose Doctor](/features/compose-doctor) for the full list of exposure-aware findings.
|
|
|
|
## Networks
|
|
|
|
<Frame>
|
|
<img
|
|
src="/images/compose-networking/networking-networks.png"
|
|
alt="The networks section showing one network row: 'arr-net' with a blue external badge, indicating the network is expected to already exist on the host"
|
|
/>
|
|
</Frame>
|
|
|
|
The Networks section lists every network the effective model declares:
|
|
|
|
| Element | What it shows |
|
|
|---------|--------------|
|
|
| **Name** | The resolved Docker network name Compose will use. |
|
|
| **Key** | The Compose key in parentheses, when it differs from the resolved name. |
|
|
| **external** badge | The network is expected to already exist on the host. The stack does not create or remove it on deploy. |
|
|
| **internal** badge | The network has no outbound connectivity; containers on it cannot reach the internet or the host network. |
|
|
| **created by stack** badge | Deploying the stack will create this network; it is absent until then. |
|
|
|
|
When a stack declares no explicit networks, the section shows **default network only**: all services share the implicit Docker bridge that Compose creates automatically.
|
|
|
|
External networks that do not exist on the node when you deploy will cause the deploy to fail. Compose Doctor flags missing external networks before you apply a change.
|
|
|
|
## Services
|
|
|
|
<Frame>
|
|
<img
|
|
src="/images/compose-networking/networking-services.png"
|
|
alt="The services section showing a card for the 'swag' service with network membership on 'arr-net', two published ports (443/tcp and 80/tcp), each with an amber 'all interfaces' badge indicating they are bound to 0.0.0.0"
|
|
/>
|
|
</Frame>
|
|
|
|
Each service gets a card that summarises its networking configuration as Compose will actually apply it.
|
|
|
|
### Network membership and aliases
|
|
|
|
The card lists the networks each service belongs to. When a service declares `aliases:` for a network, those names appear in parentheses after the network key. Aliases are additional DNS names the service is reachable by within that network: any other service on the same network can connect to this one using the alias as a hostname, in addition to the default service name.
|
|
|
|
### Port bindings
|
|
|
|
Published ports appear with a badge indicating which interface they are bound to on the host:
|
|
|
|
| Badge | Colour | What it means |
|
|
|-------|--------|---------------|
|
|
| **all interfaces** | Amber | The port is bound to `0.0.0.0` (or `::` for IPv6), making it reachable from every network the host is attached to. |
|
|
| **loopback** | Green | The port is bound to `127.0.0.1` (or `::1`), reachable only from the host itself. |
|
|
| *Specific IP* | Neutral | The port is bound to the address shown. |
|
|
|
|
Port ranges appear as `startPort-endPort/protocol`, for example `8000-8002/tcp`.
|
|
|
|
### Network modes
|
|
|
|
When a service uses `network_mode:` instead of individual network attachments, the mode appears as an amber badge beside the service name:
|
|
|
|
- **`network_mode: host`**: the service shares the host network stack entirely. Every container port is accessible directly on the host, even without any `ports:` entries. The card shows **all container ports / host-exposed** to make this explicit.
|
|
- **`network_mode: none`**: the service has no network connectivity at all.
|
|
- **`network_mode: service:<name>`** or **`network_mode: container:<name>`**: the service shares another container's network namespace.
|
|
|
|
### Extra hosts
|
|
|
|
When a service declares `extra_hosts:`, the resolved hostname-to-IP mappings are listed at the bottom of the card. These entries are injected into the container's `/etc/hosts` file at startup.
|
|
|
|
## Runtime drift
|
|
|
|
<Frame>
|
|
<img
|
|
src="/images/compose-networking/networking-runtime-matches.png"
|
|
alt="The runtime drift section showing a green card with a globe icon and the text 'runtime matches compose' in uppercase"
|
|
/>
|
|
</Frame>
|
|
|
|
When the node is reachable, the tab compares the declared effective model against the live Docker state and reports where they disagree. Four types of drift are detected:
|
|
|
|
| Finding | What it means |
|
|
|---------|---------------|
|
|
| **Attached to undeclared network** | A running container is connected to a network the Compose file does not declare for that service. Common after a manual `docker network connect` or a Compose file change that has not been applied yet. |
|
|
| **Foreign network attachment** | A container from this stack is connected to a network owned by a different stack. Cross-stack networking the file does not account for. |
|
|
| **Declared but unused** | A network is declared in the Compose file but no currently running service is connected to it. Often seen when a service is stopped or removed without `docker compose down`. |
|
|
| **Missing from runtime** | A network is declared but does not exist in Docker. The stack may not have been deployed, or the network was deleted externally. |
|
|
|
|
System-managed networks (`bridge`, `host`, `none`) and Docker's implicit default bridge are excluded from all drift findings.
|
|
|
|
When the runtime matches the Compose file, the section shows a green **runtime matches compose** card.
|
|
|
|
When Docker is not reachable, the section shows **runtime unavailable, showing the declared model only**. The networks, ports, and exposure facts are still accurate; drift comparison resumes once the node is reachable.
|
|
|
|
**Relationship to the Drift tab:** the runtime drift shown here uses the same comparison logic as the [Drift Detection](/features/stack-drift) tab. The difference is history: the Drift tab records findings over time and shows when drift first appeared and when it cleared. The Networking tab always shows the current live state.
|
|
|
|
## Doctor findings
|
|
|
|
When Compose Doctor is available on the active node, a prompt at the bottom of the Networking tab directs you to the Doctor tab for deploy and security checks. The Doctor tab reads the same effective model and, when exposure intents are set, adds five exposure-aware findings on top of its standard checks:
|
|
|
|
1. A service classified **internal** or **same-node** that publishes a host port.
|
|
2. A database or admin image published on all interfaces.
|
|
3. A stack that publishes ports but has no exposure intent set.
|
|
4. A published port that the Stack Dossier's documented access URLs do not mention.
|
|
5. Reverse-proxy labels with no documented URL or reverse-proxy intent set.
|
|
|
|
See [Compose Doctor](/features/compose-doctor) for the complete check set and severity levels.
|
|
|
|
## Creating networks
|
|
|
|
<Frame>
|
|
<img
|
|
src="/images/compose-networking/networking-create-dialog.png"
|
|
alt="The Create network dialog showing a Name field, a Driver dropdown set to bridge, optional Subnet and Gateway inputs, and Internal and Attachable toggles"
|
|
/>
|
|
</Frame>
|
|
|
|
Admins can create a new Docker network directly from the Networking tab using the **create network** button in the panel header. This is the same action available from the Resources Hub Networks tab.
|
|
|
|
| Field | Required | Description |
|
|
|-------|----------|-------------|
|
|
| **Name** | Yes | The Docker network name. Must be unique on the node. |
|
|
| **Driver** | Yes (default: bridge) | `bridge` for isolated single-host networks; `overlay` for multi-host Swarm networks; `macvlan` to assign MAC addresses; `host` or `none` for special cases. |
|
|
| **Subnet** | No | CIDR notation, e.g. `172.20.0.0/16`. Docker chooses a subnet automatically when left blank. |
|
|
| **Gateway** | No | Gateway IP for the subnet, e.g. `172.20.0.1`. |
|
|
| **Internal** | No | Prevents outbound connectivity from containers on this network. |
|
|
| **Attachable** | No | Allows containers outside Compose to connect to the network manually. |
|
|
|
|
After the network is created, the Networking tab refreshes automatically. The network appears in the Networks section of any stack that declares it as `external:`.
|
|
|
|
<Note>
|
|
Creating a network here does not attach it to the current stack. To use the new network in a stack, add it to the Compose file under `networks:` with `external: true` (since Sencho created it, not the stack) and redeploy.
|
|
</Note>
|
|
|
|
## Limitations
|
|
|
|
- **No modify or delete.** Sencho can create networks (via the create network dialog) but never modifies or deletes existing networks from this tab. Cleanup is handled by `docker compose down` or the Resources Hub prune actions.
|
|
- **Structural fields only.** Environment variable values and label values are never returned. Secrets interpolated into structural fields (network `name:`, ports, `extra_hosts`) are resolved and do appear.
|
|
- **Runtime drift requires Docker reachability.** When the node is not reachable, the tab shows the declared model but cannot compare against the live state.
|
|
- **Capability-gated tab.** The Networking tab only appears when the active node reports that it supports Compose Networking. Older nodes hide the tab until they are updated.
|
|
- **Render failure blocks all facts.** If `docker compose config` fails, the tab cannot show any networking information until the model can be rendered. The error message is shown, but raw Docker output is redacted.
|
|
|
|
## Troubleshooting
|
|
|
|
<AccordionGroup>
|
|
<Accordion title="The Networking tab is not there">
|
|
The tab appears once the active node advertises support for it. A node running an older version of Sencho hides the tab until it is updated.
|
|
</Accordion>
|
|
<Accordion title="The view says the runtime is unavailable">
|
|
Sencho could not reach Docker on that node, so it shows the declared Compose model only and skips runtime drift. The networks, ports, and exposure facts are still accurate; the live comparison resumes once the node is reachable.
|
|
</Accordion>
|
|
<Accordion title="It says the model cannot render">
|
|
`docker compose config` could not produce an effective model, usually a YAML error, an unresolved include or merge, or a required variable with no value. Fix the reported problem in the Compose file and reopen the tab.
|
|
</Accordion>
|
|
<Accordion title="I cannot change the exposure intent">
|
|
Editing the intent requires stack edit access. With read-only access you can see the current classification but not change it.
|
|
</Accordion>
|
|
<Accordion title="The runtime matches compose but I changed the Compose file">
|
|
The drift comparison compares the declared model against what is currently running in Docker, not against what Docker would run if you deployed now. The runtime reflects the last deploy. Deploy the updated file to bring the runtime in line with the file, at which point the comparison clears.
|
|
</Accordion>
|
|
<Accordion title="I see a foreign network attachment I did not configure">
|
|
A foreign network attachment means a container from this stack is connected to a network owned by a different stack. This can happen when two stacks share a network by each declaring it as `external:`, when you ran `docker network connect` manually, or when a previously external network changed ownership. Check the Compose files for both stacks and compare against what the Docker daemon shows with `docker network ls` and `docker network inspect`.
|
|
</Accordion>
|
|
<Accordion title="A service shows no network membership">
|
|
A service with no explicit `networks:` block attaches to the stack's implicit default network, which Docker creates automatically. The service card shows no named network membership in that case. Services on the same default network can still communicate with each other using the service name as a hostname.
|
|
</Accordion>
|
|
</AccordionGroup>
|
|
|
|
## Related
|
|
|
|
<CardGroup cols={2}>
|
|
<Card title="Compose Doctor" icon="stethoscope" href="/features/compose-doctor">
|
|
Runs preflight checks against the same effective model, including the five exposure-aware findings that rely on the intents set in the Networking tab.
|
|
</Card>
|
|
<Card title="Drift Detection" icon="code-compare" href="/features/stack-drift">
|
|
Shows the same four runtime drift types with a persistent history, so you can see when drift first appeared and when it cleared.
|
|
</Card>
|
|
<Card title="Resources Hub" icon="network-wired" href="/features/resources">
|
|
Host-wide view of every Docker network and container attachment on the node, independent of which stack they belong to.
|
|
</Card>
|
|
<Card title="Environment and Secrets Guardrails" icon="shield-halved" href="/features/environment-guardrails">
|
|
Documents which fields Sencho reads and which it redacts, and how to keep secrets safe from interpolation into structural fields.
|
|
</Card>
|
|
</CardGroup>
|