Glossary
Each technical name in these docs, with a short definition.
In a page, a name with a dotted line has a definition. Put the pointer on the name to read it.
- access token
- A secret text that you create on GitHub or GitLab. A program that has it can read your repositories.See also: scope
- account
- The one administrator of a Ferry server: an email and a password. You sign in to the dashboard with it.
- account endpoint
- An API address below
/api/v1/auth. These addresses control the password, the sessions and the API tokens.See also: endpoint - ACME
- The protocol that a server uses to ask a certificate authority for a certificate, with no person in the middle.See also: certificate authority, HTTP-01 challenge
- action
- What an apply does to one resource:
create,updateorunchanged.See also: apply - actual state
- What runs at this moment: the containers and the ports that Docker reports.See also: desired state, reconciler
- alias
- A name that Docker gives to a container on a network. Other containers use this name, not an IP address.See also: private network
- Alpine
- A small Linux system. An image that is built on Alpine uses less disk space.See also: image
- anchor
- The part of a link after the
#. It opens the page at one heading. - apex domain
- The domain itself, with no name before it:
example.com. DNS providers write it as@.See also: subdomain - API
- Application programming interface: the HTTP addresses that programs call to control Ferry. The CLI and the dashboard use the API.See also: API token
- API token
- A secret text that proves who you are to the API. Programs send it with each request.
- apply
- The operation that reads a blueprint, then creates what is not there and updates what changed.See also: blueprint, dry run
- archive
- One file that contains many files and folders. A
.tar.gzarchive is also compressed. - Argon2id
- A hash function for passwords. It is slow on purpose, so an attacker cannot try many passwords quickly.See also: SHA-256
- authentication
- The test of who sends a request. Ferry accepts a session cookie or an API token as the proof.See also: session cookie, API token
- auto-deploy
- A setting of a service. When it is on, a push to the branch starts a deploy.See also: webhook
- autoscaling
- A system that changes the number of instances by itself when the load changes. Ferry does not have it.See also: scaling
- background
- A program in the background does not keep the terminal. You can close the terminal and the program continues.See also: foreground
- background worker
- A service that runs all the time and has no port. It does work that no request waits for.
- backoff
- A wait before a new try. The wait becomes longer after each failure.
- backup
- A copy of your data that you keep in a different place. You use it to get the data back after a loss.
- base domain
- The first domain of a Ferry server. It comes from
ferryd --base-domain. Its default islocalhost.See also: domain of the server - base image
- The image that a Dockerfile starts from. It contains a small system and the tools of one language.See also: Dockerfile
- base URL
- The start of each URL of the API: the address of the server, then
/api/v1. - bearer token
- A token that a client sends in the header
Authorization: Bearer <token>.See also: API token - binary
- The program file that a compiler makes from Go or Rust code. It runs without the compiler.
- blocking work
- Work that keeps a thread busy for a long time, for example heavy file work. Other tasks on that thread must wait.
- blue-green deploy
- A deploy that starts the new instances next to the old instances, then moves the traffic. It is the default.See also: zero downtime, recreate
- blueprint
- A YAML file (
ferry.yamlorrender.yaml) that describes your services and datastores. Ferry creates or updates them from the file. - body
- The data of an HTTP request or answer. It comes after the headers.See also: header
- boolean
- A value that is true or false.
- branch
- One line of work in a git repository. Ferry deploys the newest commit of the branch that you choose.
- bridge network
- A network that Docker makes inside one machine. The containers on it can call each other. Other machines cannot reach it.See also: private network
- build argument
- A value that
docker build --build-arggives to a Dockerfile. Docker records it in the history of the image.See also: build secret - build cache
- The layers that Docker keeps from earlier builds. Docker uses a layer again when its step did not change.See also: layer
- build command
- A command that prepares your app during the build, for example
npm run build.See also: build - build context
- The folder of files that Ferry gives to the build: the repository, or its root directory.See also: build
- build secret
- A value that Docker gives to one build step only. Docker does not record it in the image.See also: build argument
- build slot
- The right to build one image. The server has 2 build slots by default (
--build-concurrency), thus it builds 2 images at a time. - BuildKit
- The build engine of Docker. It runs the steps of a Dockerfile and keeps the cache.See also: Docker, build
- bundler
- The tool that puts the source files of a site together into the files that the browser loads.
- Cache-Control
- A header that tells the browser how long it can keep a copy of a file.See also: ETag
- camelCase
- A way to write a name of many words with no space. Each word after the first starts with a capital letter:
healthCheckPath.See also: snake_case - canonical URL
- The official address of a page. It tells search engines which URL to show.
- capability
- One special right that Linux gives to a program.
CAP_NET_BIND_SERVICElets a program listen on the ports below 1024. - cargo
- The build tool of Rust. It makes the Ferry programs from the source code.
- CDN
- Content delivery network: servers of a company (for example Cloudflare) that receive the requests first and send them to your server.
- certificate
- A file that proves that a server owns a domain. HTTPS needs one. Ferry gets certificates from Let’s Encrypt.See also: Let’s Encrypt
- cgroup
- Control group: the Linux function that measures and limits the memory and CPU of a set of processes. Docker makes one for each container.See also: kernel
- change feed
- One stream of events from the API. It tells each change on the server: what changed, not the new value.See also: event, Server-Sent Events
- CI
- Continuous integration: a system that runs your tests after each push. GitHub Actions is a CI system.
- clap
- The Rust library that reads the commands and the flags of a program. It also writes the
--helptext. - clear text
- Data with no encryption. Each machine on the network path can read it.See also: HTTPS
- CLI
- Command-line interface: the
ferrycommand. You type commands in a terminal and the CLI sends them to the server.See also: ferryd - clone
- To download a copy of a git repository. Ferry clones your repository before each build.See also: repository
- code splitting
- The build makes one file for each page. The browser loads the file only when it needs the page.
- command palette
- A search box that opens on top of the page. You type a name, then it opens a page or starts an action.
- commit
- One saved version of the code in git. A commit has an identifier named SHA.
- config file
- The file where
ferry loginsaves the server URL and the API token:~/.config/ferry/config.json.See also: API token - connection pooler
- A program between your apps and a database. With it, many app connections share a small number of database connections.
- connection string
- One URL that contains all that an app needs to connect to a database: user, password, host, port and database name.See also: datastore
- constant-time comparison
- A comparison that always takes the same time. The time tells an attacker nothing about the secret.
- container
- A process that Docker starts from an image and keeps apart from the other processes of the machine.See also: image, instance
- Content Security Policy
- CSP: a header that tells the browser which scripts and files a page can load.
- content type
- The value of the header
Content-Type. It tells the format of the body, for exampleapplication/json.See also: body - CORS
- Cross-origin resource sharing: headers that let a page of another origin call an API from a browser. Ferry sends none.See also: origin
- CPU
- The part of a machine that does the calculations. One CPU is one core. A server has one or more cores.See also: CPU limit
- CPU architecture
- The family of the processor of a machine, for example x86-64 or ARM64. An image runs on one architecture.
- CPU limit
- The most CPU time that one container can use. At the limit, the container becomes slower. It does not stop.See also: CPU, throttle
- CPU quota
- The function of the Linux kernel that applies a CPU limit. Its full name is CFS quota.See also: CPU limit, kernel
- crate
- A package of Rust code. A crate is a library that other crates use, or a program.
- cron expression
- Five fields that give a schedule: minute, hour, day of month, month and day of week.See also: schedule
- cron job
- A service that runs a command on a schedule (for example each night), then stops.
- CSS custom property
- A CSS value with a name that starts with
--. Other rules read it withvar(). - curl
- A command that sends one HTTP request and prints the answer.
- custom domain
- One more hostname that you add to one service, for example
www.example.com.See also: domain of the server - dashboard
- The web pages of your Ferry server. You use them in a browser to create and control services.
- dashboard host
- The hostname on which the proxy serves the dashboard and the API. It comes from
ferryd --dashboard-host. - data directory
- The folder where
ferrydkeeps its state: the database, the logs, the uploads and the certificates. The default is./ferry-data. - datastore
- A Postgres or Redis database that Ferry runs for you, with its data on a volume.See also: volume
- debug build
- The default build of
cargo. It compiles quickly and the programs go totarget/debug/.See also: release build - default domain
- The domain of the server that Ferry uses when it shows the URL of a service.See also: domain of the server
- degraded
- The state of a service that runs fewer instances than you asked for.See also: reconciler
- delivery
- One webhook request from GitHub. The header
X-GitHub-Deliverygives its id.See also: webhook - dependency
- A library that your app needs. A file such as
package.jsonorrequirements.txtlists the dependencies.See also: package manager - deploy
- One release of a service. Ferry builds an image, starts new instances, tests them, then sends the traffic to them.See also: build, health check
- deploy hook
- A secret URL. A request to this URL starts a deploy of one service.
- deploy log
- The log of one deploy: the build output and the steps that Ferry does.See also: log, deploy
- deploy queue
- The deploys of one service that wait for their turn. Their status is
queued.See also: deploy worker - deploy worker
- A background task of the engine. It runs the deploys of one service, one at a time, in order.See also: deploy queue, build slot
- design token
- A value of the design that has a name, for example a color or a radius. Each project reads it from one file.
- desired state
- What must run, as written in the Ferry database: services, live deploys, number of instances.See also: reconciler
- dev server
- A local web server for development. When you save a file, it builds the code again and updates the page.
- devDependencies
- The packages of
package.jsonthat only the build needs, for example the build tools. - disk
- Storage for one service that stays between deploys. It is a Docker volume at a path that you choose.See also: volume
- DNS
- Domain Name System: the directory of the internet. It gives the IP address of a server for a domain name.See also: DNS record
- DNS cache
- The memory of a DNS server. It keeps an answer for some time and gives it again without a new search.See also: DNS
- DNS provider
- The company where you manage the DNS records of your domain. Frequently, it is the company that sold you the domain.See also: DNS record
- DNS record
- One line in the DNS of your domain. An A record gives an IP address. A CNAME record points to another name.
- DNS zone
- All the DNS records of one domain at your DNS provider.See also: DNS provider
- doc comment
- A comment in Rust code that starts with
///. Tools read it as the description of the item below it. - Docker
- The program that builds images and runs containers. Ferry tells Docker what to do.See also: image, container
- Docker context
- A name in Docker for one daemon and its address. Colima and OrbStack each make a context.
- Docker daemon
- The part of Docker that stays in the background. It builds images and runs containers when a program asks.See also: Docker socket
- Docker Desktop
- The Docker app for macOS and Windows. It runs the containers in a virtual machine.See also: virtual machine
- Docker Engine API
- The HTTP interface of Docker. A program calls it to create, start, stop and read containers, images, volumes and networks.See also: Docker
- Docker host
- The machine that Docker runs on. Its CPUs and its memory are all that the containers can use.See also: Docker
- Docker root directory
- The folder where Docker keeps its images, containers and volumes.
- Docker socket
- A special file on the machine. Programs talk to the Docker daemon through it.
- Dockerfile
- A text file with the steps that build an image.See also: image
- domain
- A name that you own on the internet, for example
example.com.See also: DNS - domain of the server
- A domain that Ferry serves all public services under. With
example.com, a service namedshopanswers atshop.example.com.See also: base domain, custom domain - drop guard
- A Rust value that runs its cleanup code when the function ends, also after a failure.
- dry run
- A test of a blueprint. It shows what Ferry will create or change, and it changes nothing.See also: blueprint
- DTO
- Data transfer object: a type that gives the form of the data in a request or in an answer of the API.
- encryption at rest
- Encryption of the data on a disk. Without it, each person who can read the file can read the data.
- end-to-end test
- A test that runs the real parts together, with a real Docker daemon.See also: gated test
- endpoint
- One address of an API, for example
/healthz.See also: API - engine
- The part of
ferrydthat runs the deploys, the reconciler, the cron jobs and the datastores. Its crate isferry-engine.See also: reconciler, deploy worker - entry
- One item of a list in a blueprint. An entry describes one service, one database, one env group or one variable.See also: blueprint
- env group
- A set of environment variables with a name. You link it to all the services that need the same values.
- environment file
- A text file with one
NAME=valueon each line. systemd gives these values to the program as environment variables.See also: environment variable - environment variable
- A value with a name that Ferry gives to your app when it starts. Example:
DATABASE_URL.See also: env group, reference - error code
- The
codefield of an API error, for examplenot_found. It is stable: programs can test it.See also: status code - escape
- To write a special text so that a program reads it as plain text.
$${{ name }}gives the literal text${{ name }}. - ESLint
- The tool that runs the lints of JavaScript and TypeScript code.See also: lint
- ETag
- A header that identifies one version of a file. The browser sends it back to ask if its copy is current.
- event
- A record of something that occurred on the server, for example "deploy live" or "instance crashed".
- EventSource
- The object of a browser that reads a Server-Sent Events stream. It connects again by itself. It cannot set headers.See also: Server-Sent Events
- exit code
- The number that a command gives to the shell when it stops.
0is a success. Each other number is a failure. - external URL
- The connection string for the server itself. Its host is
127.0.0.1, with a port of the server.See also: connection string, host port - Ferry key
- A blueprint key that Ferry adds to the
render.yamlformat:port,memoryLimitandcpuLimit. Render has no such key.See also: blueprint - ferryd
- The Ferry server. It is one program that runs on your machine and controls Docker.See also: CLI, dashboard
- file mode
- The digits that tell who can read, write or run a file. With
600and700, only the owner has access. - firewall
- A filter that blocks the network connections to a machine, but not on the ports that you open.See also: port
- fixture
- Fixed data or a small app that a test uses as its input.
- flag
- An option that you add to a command. It starts with
--, for example--json. - foreground
- A program in the foreground keeps the terminal and writes its output there until it stops.See also: background
- fork
- The system call that makes a new process from a process that runs.See also: process
- fork bomb
- A program that starts new processes with no end. It can fill a machine that has no limit.See also: pids limit
- formatter
- A tool that writes the code in one standard layout.
cargo fmtis the formatter of Rust. - free-disk check
- The test that Ferry does before a build or a pull: the disk must have enough free space.
- frontmatter
- The lines between
---at the top of a page file. They give the title and the description. - Fumadocs
- The framework of this docs site. It makes the pages, the sidebar and the search from MDX files.
- gated test
- A test that runs only when a variable is set. Without the variable, it prints
skippedand passes. - generated secret
- A random value of 64 hex characters (256 bits). Ferry makes it for a variable that has
generateValue: true. - git cache
- The copy of the repository that Ferry keeps on the server for one service. The next deploy gets only the new commits.See also: repository
- git connection
- A GitHub or GitLab account that gave your Ferry server the permission to read its repositories.See also: provider, repository
- git submodule
- A git repository that is a folder of another git repository.See also: repository
- GitHub App
- An application on GitHub that belongs to your account. Ferry creates one for your server. It reads only the repositories that you choose.See also: git connection
- grace period
- The time that a container has to stop by itself. After that time, Docker stops it by force.See also: SIGTERM, SIGKILL
- graceful shutdown
- A stop in order: the server completes the requests in progress, then closes each part, then exits.
- group
- A set of Linux users. A right that the group has applies to each of its members.
- gRPC
- A protocol that programs use to call each other. It needs HTTP/2 from one end to the other.See also: HTTP/2
- hash
- A text that a program calculates from a password. The program can compare it, but nobody can read the password from it.
- header
- One line of an HTTP request or answer that has a name and a value, for example
Host: shop.example.com.See also: Host header - health check
- The test that tells Ferry that a new instance can receive traffic.
- hex character
- One of the 16 characters
0to9andatof. Programs write random values and hashes with them. - high availability
- A setup that stays online when one container or one machine fails.See also: replica
- history URL
- A normal path, for example
/services/api/logs, that the app reads in the browser. The server has no file for it. - HMAC
- A signature that the sender calculates from a message and a shared secret. The receiver calculates it again and compares.See also: webhook
- Host header
- The header of a request that gives the hostname that the client wants. The proxy reads it to find the service.See also: header, hostname
- host port
- A port of the server that Docker connects to a port of a container.See also: port
- hostname
- The name of a machine or a site on a network, for example
api.example.com. - hot module replacement
- HMR: the dev server puts a changed file into the open page immediately. You do not reload the page.
- HTTP-01 challenge
- The test of ACME: the certificate authority asks the host for a secret file on port 80. A correct answer proves control of the hostname.See also: ACME
- HTTP/2
- A newer version of HTTP. It sends many requests at the same time through one connection.
- HttpOnly
- A flag of a cookie. The browser sends the cookie, but a script in the page cannot read it.See also: cookie
- HTTPS
- HTTP with encryption. The browser and the server use a certificate to keep the traffic private.See also: certificate
- icon rail
- The column of icons on the left side of the dashboard. Each icon opens one main page.See also: dashboard
- id
- The identifier that Ferry gives to a resource: a prefix and 20 hex characters, for example
srv-60f5973b037e4478ae7b. - idempotent
- An operation is idempotent when a second run with the same input changes nothing.
- ignore file
- A text file that lists the files to leave out:
.gitignore,.ignore,.ferryignoreor.dockerignore. - image
- A package that contains your app and all that the app needs to run. Docker starts containers from an image.See also: container, build
- image history
- The list of the steps that made an image. Each person who has the image can read it.See also: image
- injected variable
- An environment variable that Ferry adds to each container, for example
PORTorFERRY_SERVICE_NAME.See also: environment variable - instance
- One running container of a service. A service can have many instances that do the same work.See also: container
- instance_id
- The file of the data directory that holds the identity of one Ferry server.
- integration test
- A test in
crates/<crate>/tests/. It uses the crate from the outside, as another crate does. - internal address
- The name and the port of a service on the private network, for example
api:3000.See also: private network - internal URL
- The connection string for the private network. Its host is the name of the datastore, for example
app-db:5432.See also: connection string, private network - invalidation
- A mark on data in the cache that says the data is stale. The library then gets the data again.
- invariant
- A condition that is always true at one point of the code.
- IP address
- The number of a machine on a network, for example
203.0.113.10. Machines use it to find each other.See also: DNS - IP allow list
- A list of IP addresses. Only these addresses can connect.
- IPv6
- The newer format of IP addresses, for example
2001:db8::10. AnAAAArecord gives an IPv6 address. AnArecord gives an IPv4 address.See also: IP address, DNS record - job
- A command that runs one time in a new container of a service, then stops.
- journal
- The place where systemd keeps the output of the programs that it runs. The command
journalctlreads it.See also: systemd - JSON
- A text format for data that programs read. Example:
{"name": "api", "state": "live"}. - keep-alive comment
- The line
: keep-alive. The server sends it on a stream that has nothing new, to keep the connection open.See also: stream - kernel
- The center of the operating system. It gives memory and CPU time to each process, and it applies the limits.
- key
- The name on the left of the
:in a YAML file. Its value is on the right, for examplename: api.See also: YAML - key value store
- The name that Render gives to a Redis database. On Ferry, it is a Redis datastore.See also: datastore
- KiB
- Kibibyte: 1024 bytes. 32 KiB is 32,768 bytes.
- kind
- The first part of a reference. It tells if the name is the name of a datastore or of a service.See also: reference
- label
- A key and a value that Docker keeps on a container. Ferry reads the labels to find its own containers.
- layer
- The result of one step of a Dockerfile. An image is a stack of layers.See also: build cache
- Let’s Encrypt
- A free service that gives HTTPS certificates. It first tests that your server controls the domain.
- lint
- A check that finds common errors and bad style in the code.
cargo clippyruns the lints of Rust. - live deploy
- The deploy of a service that gets the traffic now. A service has one live deploy at most.See also: deploy, snapshot
- liveness probe
- A small request that tells you if a program is alive.
- load balancer
- A machine or a cloud product that receives the traffic and gives it to one or more servers.
- load balancing
- The proxy gives each new request to the next instance, in turn. All instances share the work.
- local name
- A name that has no public DNS:
localhost,*.localhost,*.local,*.internaland*.test. It gets no certificate.See also: localhost - localhost
- The name of your own machine.
127.0.0.1is its address. Other machines cannot connect to it. - localStorage
- A place in the browser where a page keeps small values. Each script of the page can read it.
- lock
- A mark on a file that one program holds. It tells other programs that the folder is in use.
- lockfile
- A file that records the exact version of each dependency, for example
package-lock.json.See also: dependency - log
- The lines of text that a program writes while it runs. You read them to know what occurred.
- log driver
- The part of Docker that stores the output of containers. The default driver,
json-file, writes files on the disk. - log rotation
- When a log file is full, Docker starts a new file and deletes the oldest file. The log cannot fill the disk.See also: log driver
- lucide
- A set of icons. The dashboard and the docs site use it.
- mapping
- A group of
key: valuepairs in YAML. Each entry ofservicesis a mapping.See also: YAML - marker volume
- The Docker volume
<prefix>-owner. It records which data directory owns the name prefix.See also: instance_id - maxmemory
- The Redis setting for the most memory that Redis uses for data. When it is full, Redis refuses writes.
- MDX
- Markdown that can also contain components, for example
<Diagram>. - memory limit
- The most memory that one container can use. Above it, the kernel stops the process of the container.See also: OOM kill, resource limit
- merged environment
- All the variables that a service gets: the injected variables, then its env groups, then its own variables.See also: precedence
- Mermaid
- A text format for diagrams. The browser draws the diagram from the text.
- method
- The verb of an HTTP request.
GETreads.POSTcreates or starts.PUTandPATCHchange.DELETEremoves. - metric
- A number that measures a container at one moment, for example its CPU use or its memory use.
- MiB
- A unit of memory and of disk space. 1 MiB is 1024 × 1024 bytes. 1 GiB is 1024 MiB.
- migration
- A script that changes the structure of a database, for example to create a table.
- millicore
- One thousandth of a CPU core.
500mis 500 millicores: half a core.See also: CPU - mock
- A stand-in for a real part in a test. It records the calls that it gets and does no real work.
- monorepo
- One repository that contains many apps, each in its own folder.See also: root directory
- mount path
- The folder in the container where the disk shows, for example
/data.See also: disk - mutation
- A request that changes data on the server.See also: query
- name prefix
- The start of the name of each Docker resource of one Ferry server. The default is
ferry. - NAT
- Network address translation: a router gives one public address to machines that have private addresses.See also: public address
- network interface
- The part of a machine that connects it to a network. Each network interface has an IP address.See also: IP address
- Next.js
- A React framework. It builds this docs site.
- nginx
- A web server program. Ferry uses it to send the files of a static site to the browser.See also: static site
- Node.js
- The program that runs JavaScript outside a browser. The builds of the dashboard and of the docs site need it.See also: npm
- npm
- The package tool of Node.js. It gets the libraries of a project and runs its build.
- OAuth application
- An application that you create on GitLab for your server. After you authorize it, Ferry can read your repositories. Ferry never gets your password.See also: redirect URI, scope
- one-off job
- A command that you start one time with
ferry run. It runs in a new container of a service, then stops.See also: run - OOM kill
- Out of memory: the system stops a container that uses more memory than its limit.
- OOM killer
- The part of the Linux kernel that stops a process when the machine has no free memory.See also: OOM kill
- OOM score
- A number for each process. When the machine has no free memory, the kernel first stops the process with the highest score.See also: OOM kill, kernel
- OOM watcher
- A task of the engine that listens to the
oomevents of Docker. It writes a warning in the server log for each kill.See also: OOM kill - Open Graph
- Data in a page that gives the title and the image that show when a person shares the link.
- open-file limit
- The number of files and connections that the system lets one program keep open at the same time.
- OpenAPI document
- A file that describes each address of an API in a standard format. Tools such as Swagger UI read it.See also: API
- origin
- The scheme, the host and the port of a web page, for example
https://ferry.example.com. A browser keeps pages of different origins apart. - orphan
- A container of this server whose service or datastore does not exist. The reconciler removes it.
- overcommit
- The limits of all containers together are larger than the memory of the server.See also: OOM score
- package manager
- The tool that installs the dependencies of a project: npm, Yarn, pnpm, Bun, pip, Bundler, and so on.See also: dependency
- pagination
- An API with pagination gives a long list in parts, one page for each request. The Ferry API gives the full list.
- pass
- One run of the reconciler: it compares the two states one time and repairs the difference.See also: reconciler
- PATH
- The list of folders where the terminal looks for a program when you type its name.
- Pebble
- A small ACME server for tests, from Let’s Encrypt. It gives certificates that browsers do not trust.See also: ACME
- pg_dump
- The Postgres tool that writes a full database into one file. The tool
psqlloads the file into another database. - pids limit
- The largest number of processes and threads that one container can have at the same time.See also: process, fork bomb
- pinned image
- An image that Ferry keeps with a tag of its own for one deploy. This deploy always runs the same image.See also: tag
- plan
- On Render, an instance type: a fixed quantity of memory and CPU. Ferry changes a plan into memory and CPU limits.See also: resource limit
- polling
- To ask the server again at a fixed interval, to see if something changed.
- port
- A number that identifies one program on a machine for network connections. Your app listens on a port.
- Postgres
- A database that keeps data in tables. Apps read and change the data with SQL.See also: datastore
- precedence
- The rule that tells which value wins when the same key exists in two places.See also: merged environment
- private address
- An IP address that works only in one local network, for example
192.168.1.10. Machines on the internet cannot reach it.See also: public address, NAT - private key
- The secret half of a pair of keys. The program that has it can prove its identity or read encrypted data.
- private network
- A Docker network that only your services and datastores are on. They call each other by name, for example
api:3000. - private service
- A service with a port but no public URL. Only your other services can call it.See also: private network
- process
- One program that runs on a machine. An app can start many processes.See also: thread
- Procfile
- A text file named
Procfile. Each line has a name and a start command, for exampleweb: python app.py.See also: start command - property
- The last part of a reference. It tells which value you want, for example
hostorconnectionString.See also: reference - provider
- The site that keeps your git repositories: GitHub or GitLab.
- proxy
- The part of Ferry that receives each HTTP request and sends it to an instance of the correct service.See also: load balancing
- psql
- The command-line client of Postgres. It sends SQL to a database.
- public address
- The IP address that machines on the internet use to reach your server.See also: IP address
- public URL
- The address that a browser on the internet uses to open your service, for example
https://shop.example.com.See also: hostname - publish directory
- The folder of a static site that nginx serves, for example
dist.See also: static site - published port
- A port of the host that Docker connects to a port of a container. Ferry publishes ports only on
127.0.0.1.See also: host port, localhost - pull request preview
- A temporary copy of an app that a host makes for each pull request, to test the change.
- push
- The git command that sends your commits to the repository on GitHub or GitLab.See also: commit
- query
- A request that reads data from the server. TanStack Query keeps the answer in a cache.See also: mutation
- query string
- The part of a URL after the
?, for example?key=abc. - quota
- A limit on the disk space that one container or one volume can use. Ferry sets none.
- rate limit
- The largest number of requests that a service accepts in a period of time.
- React
- A JavaScript library that builds a web page from components.
- React Router
- A library that shows the correct page for each URL of a single-page app.See also: history URL
- reconciler
- The loop in Ferry that compares what must run with what Docker runs, then repairs the difference.
- recreate
- A deploy that stops the old instance before it starts the new instance. Ferry uses it for a service with a disk.See also: disk
- redact
- To replace a secret with
***before a text goes into a log or an answer. - redirect
- An answer that tells the browser to go to another URL. Ferry uses the status code
308to send HTTP to HTTPS.See also: status code - redirect URI
- The address that the provider sends your browser back to after you authorize.
- Redis
- A database that keeps keys and values in memory. Apps use it as a cache or as a queue.See also: datastore
- reference
- A value written as
${{…}}. Ferry replaces it with the real value (for example a database URL) when the service starts. - registrar
- A company that sells domain names.See also: DNS provider
- registry
- A server that stores images. Docker Hub is a registry.See also: image
- release build
- A build with full optimization. It compiles slower, and the programs run faster. They go to
target/release/.See also: debug build - Render
- A company that runs apps on its own servers. Ferry does the same work on a server that you control.
- replay
- An attack that sends a copy of an old valid request one more time.
- replica
- A second database server that keeps a copy of the data of the first server.
- repository
- A folder of code with its history, kept by git. Also called a repo.See also: branch, commit
- resolve
- A name resolves to an address when the DNS gives this address for the name.See also: DNS
- resource
- A thing that Ferry controls and that a blueprint can describe: a service, a datastore or an env group.
- resource limit
- The most memory and CPU that one container can use.See also: OOM kill
- REST API
- An API that uses plain HTTP requests. The URL names a resource. The method (
GET,POST,DELETE) names the action.See also: API, method - restart
- A deploy that uses the live image again, with the current settings and variables. Nothing is built.
- restart policy
- The Docker rule that says what to do when a container stops. With
unless-stopped, Docker starts the container again. - resume
- To start the instances of a suspended service again, from the live deploy.See also: suspend
- reverse proxy
- A program that receives the requests from the internet and sends them to another program. nginx, Caddy and Traefik are reverse proxies.See also: proxy
- RFC 3339
- A standard text format for a date and a time, for example
2026-09-27T07:38:34.231568Z.See also: timestamp - role-based access control
- Each user has a role, and the role says what the user can do.
- rollback
- A deploy that uses the image of an earlier deploy again.
- root
- The administrator account of a Linux machine. It can read, change and delete all things.See also: sudo
- root directory
- The folder of your code where Ferry builds the service. The default is the top of the repository.See also: monorepo
- rootless Docker
- A Docker daemon that runs as a normal user, not as root.
- round-robin
- A rule of turns: the first request goes to the first instance, the next request to the next instance, then the list starts again.See also: load balancing
- route
- The link between a hostname and the instances of a service. The proxy uses it to send each request.See also: proxy
- route table
- A list in the memory of
ferryd. For each hostname, it gives the addresses of the instances. The proxy reads it for each request.See also: proxy, upstream - route watcher
- The loop in Ferry that lists the instances each second and updates the routes of the proxy.See also: route
- router
- The part of the API that sends each request to the function for its path.
- run
- One execution of a job: one new container, one command, one log and one exit code.See also: job, one-off job, cron job
- runtime
- The language environment of your app (Node, Python, Go, Rust, Ruby, static). Ferry finds it from your files and writes the Dockerfile.
- runtime log
- What the containers of a service write while they run. Docker keeps it as long as the containers exist.See also: log, stdout, stderr
- Rust
- The programming language of Ferry.See also: cargo
- scalar
- One simple value in YAML: a text, a number or a boolean. A list and a mapping are not scalars.See also: YAML
- scaling
- A change of the number of instances of a service.See also: instance, autoscaling
- schedule
- The times at which a cron job runs. You write it as a cron expression, for example
0 3 * * *.See also: cron job, cron expression - scheduler
- The part of Ferry that starts a run of a cron job at each time of its schedule.See also: schedule
- scope
- One permission of a token or of an application, for example
read_repository. - secret file
- On Render, a file with secret text that the host puts in the container of a service.
- self-hosted
- You run the program on a machine that you control, not on the machines of a company.
- self-signed certificate
- A certificate that a server makes for itself. No certificate authority signed it, thus browsers show a warning.See also: certificate
- server log
- The log that
ferrydwrites about its own work: failed deploys, OOM kills, proxy warnings.See also: ferryd - server token
- An API token that
ferrydwrites in its data directory at the first start. Scripts on the server use it.See also: API token - Server-Sent Events
- SSE: one HTTP answer that stays open. The app sends new lines of data to the browser when it has them.
- service
- One app that Ferry builds and runs for you. A service has a name, a type, a source and settings.See also: instance, deploy
- service id
- The identifier that Ferry gives to a service:
srv-and 20 hex digits. Commands accept the id or the name. - service lock
- A lock that each service has. Only the operation that holds it can change the containers of the service.See also: reconciler
- service manager
- A system program that starts other programs and starts them again after a crash: systemd on Linux, launchd on macOS.See also: systemd
- service type
- The kind of a service: web service, private service, background worker, cron job or static site.See also: service
- session
- The time that one browser stays signed in to the dashboard. A cookie in the browser identifies it.
- setup code
- A secret code that
ferrydmakes while the server has no account. You need it to create the account. - SHA-256
- A function that calculates a fixed value (a hash) from a text. Nobody can get the text back from the hash.See also: Argon2id
- shadcn/ui
- A set of React components that you copy into your project and change.
- shell
- The program that reads the commands that you type in a terminal, for example bash or zsh.
- SIGKILL
- The signal that stops a process immediately. The process cannot refuse it.See also: signal, exit code
- signal
- A short message that the system sends to a process, for example to tell it to stop.
SIGINTandSIGTERMask a process to stop.See also: SIGKILL - signature
- A code that GitHub computes from the request and the webhook secret. It proves that the request comes from GitHub.See also: webhook secret
- SIGTERM
- The signal that asks a program to stop. The program can save its work first.See also: SIGKILL, grace period
- Simplified Technical English
- ASD-STE100: a standard with rules for short and clear technical sentences.
- single-page app
- A web app that loads one HTML page. JavaScript then changes the page, with no full reload.
- snake_case
- A way to write a name of many words: lower case, with
_between the words, for examplebase_domain.See also: camelCase - snapshot
- The exact image, variables, command and limits of a live deploy. Ferry saves them and uses them for each new container of that deploy.
- SNI
- Server Name Indication: at the start of an HTTPS connection, the client gives the hostname. The server then chooses the certificate of that hostname.See also: certificate
- source
- Where the code of a service comes from: a git repository, a Docker image or an upload.See also: repository, image, upload
- SQLite
- A small database that is one file. Ferry keeps its own data (services, deploys, settings) in it.
- SSH
- Secure Shell: the tool that opens a terminal on another machine through an encrypted connection. It uses port 22.See also: SSH tunnel
- SSH tunnel
- A safe connection through SSH that makes a port of the server available as a port of your machine.
- staging
- A second copy of your setup where you test a change before it goes to production.
- standard input
- The channel where a program reads its input. A pipe (
|) or a file can give the input, not only the keyboard. - start command
- The command that starts your app in each container, for example
npm start.See also: Procfile - state
- What a service does now:
live,deploying,failed, and so on. Ferry computes it from the deploys and the containers.See also: service - static export
- A full site written as plain files (HTML, CSS, JavaScript, images). No program runs on the server to make the pages.See also: static site
- static site
- A service that is only files (HTML, CSS, JavaScript). Ferry serves the files with nginx.
- status code
- The number at the start of an HTTP answer.
200is a success,404is "not found",503is "not available". - stderr
- Standard error: the channel where a program writes its errors and its progress messages.See also: stdout
- stdout
- Standard output: the channel where a program writes its results. A pipe (
|) sends it to the next command.See also: stderr - store
- The part of Ferry that reads and writes the SQLite file
ferry.db. It has the desired state.See also: SQLite, desired state - stream
- An HTTP answer that stays open. The server adds data to it while the client reads.See also: Server-Sent Events
- subdomain
- A name under a domain.
shop.example.comis a subdomain ofexample.com.See also: domain - sudo
- A Linux command that runs one other command as root.See also: root
- suspend
- To stop all the instances of a service and keep its settings, its deploys and its data.See also: resume
- Swagger UI
- A web page that lists each endpoint of an API. You can try the endpoints from the page.
- swap
- Disk space that a system uses as slow memory when the real memory is full.
- symlink
- A file that points to another file or folder.
- system user
- A Linux account for a program, not for a person. No person can log in with it.See also: group
- systemd
- The Linux program that starts services when the machine boots and starts them again after a crash.
- tag
- The part of an image name after the
:. It names one version of the image, for examplealpineinnginx:alpine.See also: image - Tailwind CSS
- A CSS tool. You style an element with short class names, for example
text-primary. - TanStack Query
- A library that gets data from an API, keeps it in a cache and gets it again when it is stale.See also: invalidation
- TCP connection
- The basic link between two programs on a network. HTTP sends its requests through a TCP connection.See also: port
- terminal
- The window where you type commands and read their output.See also: CLI
- thread
- One line of work in a process. A process can have many threads that work at the same time.See also: process
- throttle
- To make a container wait when it used all the CPU time of its limit. The app runs slower.See also: CPU limit
- timeout
- The longest time that a program waits for something. After this time, the program stops the wait.
- timestamp
- The date and time when a line was written.
- TLS
- Transport Layer Security: the encryption that HTTPS uses between the browser and the server.See also: HTTPS, certificate
- TLS handshake
- The start of a TLS connection. The server shows its certificate and the two sides agree on the keys.See also: TLS
- toolchain
- The tools that build a project in one language, for example Node.js with npm.
- top-level key
- A key with no indentation. A blueprint has four:
envVarGroups,databases,servicesandprojects.See also: key - tracing
- The Rust library that Ferry uses to write its log lines. Each line has a level, for example
infoordebug. - trait
- In Rust, a list of functions that a type must have. Code that calls a trait does not know which type answers.
- trigger
- The cause of a deploy: a command, a push to git, a change of variables, and so on.
- type check
- A check that each value has the type that the code expects. It runs no code.
- TypeScript
- JavaScript with types. A compiler checks the types before the code runs.
- unit
- A file that tells systemd how to start, stop and supervise one program.See also: systemd
- unit test
- A test of one small part of the code. It is in the same file as the code and needs no other program.
- upload
- A folder of code that
ferry upsends from your machine to the server.See also: archive - upstream
- An address to which the proxy sends requests: one instance, as
127.0.0.1:<host port>.See also: route table - UTC
- Coordinated Universal Time: the reference time of the world. It has no summer time.
- utoipa
- The Rust library that makes the OpenAPI document from annotations in the code.See also: OpenAPI document
- validation
- The test of each value against the rules, before Ferry writes something.
- variable of the shell
- A value with a name that your shell gives to each command, for example
FERRY_TOKEN. You set it withexport.See also: environment variable - virtual machine
- A computer that software makes inside a real computer. It has its own system, CPUs and memory.
- Vite
- The build tool of the dashboard. It serves the code in development and makes the files for production.
- Vitest
- The test tool of the dashboard. It runs the files that end with
.test.tsor.test.tsx. - volume
- A folder that Docker keeps on the server when a container is removed. Data on a volume stays.See also: disk
- web service
- A service that answers HTTP requests and has a public URL.
- webhook
- An HTTP request that one system sends to another when something occurs. GitHub sends a webhook to Ferry after each push.
- webhook secret
- A secret text that GitHub and
ferrydshare. GitHub signs each webhook with it.See also: webhook, signature - WebSocket
- A connection that stays open between a browser and an app. The two sides send messages at any time.
- wildcard certificate
- One certificate for
*.example.com. It is good for each name directly under the domain.See also: certificate - wildcard DNS record
- A DNS record for
*.example.com. It answers for each name under the domain, thus a new service needs no new record.See also: DNS record - workspace
- A set of Rust crates in one repository.
cargobuilds and tests them together.See also: crate, cargo - x-ferry-error
- A header that the proxy adds when it answers with its own error page. Your app does not send it.See also: proxy
- YAML
- A text format for settings. Each line is
key: value. The indentation shows what is inside what.See also: blueprint - YAML anchor
- A name for a block of YAML, written
&defaults.<<: *defaultscopies the block to another place of the file.See also: YAML - zero downtime
- Your app answers during the full deploy. The old instances stop only after the new ones are ready.
- Zustand
- A small library that keeps the state of the app in the browser.