container block describes how the deployed image runs. port is the port inside the container; the process must listen on the container’s network interface. Set resource limits near the port so a reviewer can assess expected capacity:
.towbar/services/web.service.yml
Private connectivity
Set the samecontainer.network on a Service and Datastore on the same server. A Datastore’s ID is its network alias unless it sets networkAlias:
.towbar/services/web.service.yml
postgres, the Service can connect to postgres:5432. Put the credential-bearing URL in a service runtime secret, not in the manifest. A Docker network on one host does not connect containers across different servers.
Persistent storage
Use a Docker-managed named volume when a process must retain files across replacement:.towbar/services/files.service.yml
initialData applies only when adding a new volume: previous-container imports from the stopped container, while image initializes from the new image. Environment overrides replace the common volume list. Host-directory bind mounts are not accepted; keep backups of important files outside Towbar.