ArchitectureSecurity model
One server per data directory and prefix
Two safety rules prevent that one Ferry server removes the containers of another server.
Server A starts with the prefix ferry. It records its data directory on the marker volume.
1 / 4
Without these rules, a second ferryd would see the containers of the first server as orphans and remove them.
In a server, the engine lists and touches only the containers with the label ferry.instance=<prefix>.
The two rules
| Rule | How ferryd applies it |
|---|---|
| One process per data directory | It holds an exclusive lock on <data-dir>/ferryd.lock while it runs. |
| One data directory per name prefix | It records the owner of its prefix (--name-prefix, default ferry) on the marker volume <prefix>-owner. The labels of the volume are the instance_id and the path of the data directory. |
What a refusal looks like
another ferryd is already running with data directory …Error: Docker resources with prefix 'ferry' belong to another Ferry server (data dir /var/lib/ferry). Run this server with a different --name-prefix, stop the other server, or pass --take-over to adopt the resources (the other server's containers will then be managed — and possibly removed — by this one).Run more than one server
Give each server its own --name-prefix and its own --data-dir. See Multiple servers.
- The prefix belongs to another data directory.
- A new data directory finds containers with its prefix that it does not know.
--take-over is for one special case only.