Citadel
Overview

How Citadel works

Understand the parts of your installation and where your data lives.

Citadel provides centralized management for Docker Standalone and Swarm environments. It stores application configuration, coordinates deployments, and monitors workloads through a web interface and API. Docker remains responsible for running the containers.

The main parts

PartWhat it does
Citadel CoreServes the web interface and API, checks access, and runs background jobs
PostgreSQLSaves accounts, application settings, activities, and collected statistics
citadel_data volumeSaves keys used to protect secrets, signing keys, and local repository files
Local connectorLets Core manage Docker on its own host through the Docker socket
AgentLets Core connect to Docker on another reachable host
Edge AgentConnects out from a remote host to Core when inbound connections are unavailable
Swarm node agentsProvide information and operations on cluster nodes that the manager cannot supply alone

The Platform guide helps you choose a connection. You do not need an Agent for the local quick start.

Saved settings and running applications

Saving a Deployment or Stack changes Citadel's configuration. Selecting Deploy sends that configuration to Docker. Citadel then compares the saved configuration with what is actually running. An unexpected difference is called drift.

Docker applications can keep running while Citadel is stopped, but Citadel cannot monitor them or carry out operations during that time.

What to back up

Back up PostgreSQL and citadel_data together to recover your Citadel installation. Back up your applications' named volumes separately to recover their data. See the backup guide.

Citadel and its Agents have administrative access to their Docker hosts. Protect administrator accounts, use HTTPS for shared access, and give other users only the permissions they need.

On this page