How Citadel works
Understand the parts of your installation and where your data lives.
Citadel provides centralized management for Docker Standalone and Swarm environments. It stores application configuration, coordinates deployments, and monitors workloads through a web interface and API. Docker remains responsible for running the containers.
The main parts
| Part | What it does |
|---|---|
| Citadel Core | Serves the web interface and API, checks access, and runs background jobs |
| PostgreSQL | Saves accounts, application settings, activities, and collected statistics |
citadel_data volume | Saves keys used to protect secrets, signing keys, and local repository files |
| Local connector | Lets Core manage Docker on its own host through the Docker socket |
| Agent | Lets Core connect to Docker on another reachable host |
| Edge Agent | Connects out from a remote host to Core when inbound connections are unavailable |
| Swarm node agents | Provide information and operations on cluster nodes that the manager cannot supply alone |
The Platform guide helps you choose a connection. You do not need an Agent for the local quick start.
Saved settings and running applications
Saving a Deployment or Stack changes Citadel's configuration. Selecting Deploy sends that configuration to Docker. Citadel then compares the saved configuration with what is actually running. An unexpected difference is called drift.
Docker applications can keep running while Citadel is stopped, but Citadel cannot monitor them or carry out operations during that time.
What to back up
Back up PostgreSQL and citadel_data together to recover your Citadel
installation. Back up your applications' named volumes separately to recover
their data. See the backup guide.
Citadel and its Agents have administrative access to their Docker hosts. Protect administrator accounts, use HTTPS for shared access, and give other users only the permissions they need.