infra · docker swarm, dokploy, github actions, cloudflare
DevOps engineer for Docker Swarm and Dokploy, with a preview for every branch.
For a SaaS company I set up the whole hosting: a Docker Swarm cluster with a manager and several workers, run through Dokploy. A push to master goes live on its own, every feature branch gets a preview on its own subdomain, and Cloudflare sits in front. I can set up yours the same way, or take over the one you have.
- Platform
- Docker Swarm, Dokploy, Traefik
- CI/CD
- GitHub Actions, GitHub Container Registry
- DNS & CDN
- Cloudflare
- Engagement
- As a project, in your team or as advisory
- Working hours
- Mon–Fri 04:00–18:00 Buenos Aires 09:00–23:00 Berlin 03:00–17:00 New York
- Available from
- Q4 '26
What I set up
- A cluster instead of a single server: Docker Swarm with a manager and workers, so the apps are spread over several machines, and more capacity is one more worker.
- Dokploy as the control panel: apps, databases, domains and certificates in one place, with deploys and logs in the browser instead of over SSH.
- Deploys without manual steps: a push to master builds and ships a new version.
- A preview for every branch: each feature branch runs on its own subdomain, so a feature can be tested before it is merged.
- Pipelines in GitHub Actions: tests, Docker images and releases.
- Cloudflare in front: DNS, caching, redirects and firewall rules.
In production: the platform of a SaaS company
For a SaaS company, I set up the whole platform: a Docker Swarm cluster with a manager and several workers, run through Dokploy, with Cloudflare in front. Most repositories are Dokploy applications connected to GitHub. A push to master deploys a new version, and every feature branch starts a preview deployment on its own subdomain.
The backend services share their pipelines through one workflows repository: CI and releases with release-please. A template for new services starts with both already wired up.
The reference: this website
asisto.io runs on Dokploy too: nginx serves the built files, with Traefik in front. The Traefik rules live in the repository next to the code: a year of cache for files with a hash in their name, no cache for HTML so a deploy shows up at once, and HSTS plus a few security headers that cost nothing. www and a missing trailing slash are redirected in one hop, and a missing page gets the 404 in the language of its URL.
DevOps next to the rest of the stack
For me, the pipeline belongs to the code, so I set it up alongside it. The NestJS backends and Astro sites I build ship as Docker images, and the pipeline comes with them. You get one person who knows both the code and the servers, and a failed deploy doesn’t bounce between two teams.
How we can work together
- App development: hosting and pipelines as a project, or as part of a product I build, with a written scope, a demo every week, and the configuration belongs to you.
- Staff augmentation: I join your team and look after the platform alongside the product work, part-time or full-time, from three months.
- Advisory: a review of your current hosting and deploys, or a plan for moving from one server to a cluster, by the hour or as a monthly retainer.
Questions
Why Docker Swarm and not Kubernetes?
Swarm is part of Docker: a few servers join a cluster, and an app is described in much the same file as in local development. There is no separate control plane to run and upgrade. Kubernetes pays off when many teams deploy many services and someone looks after the cluster full-time. For a product on a handful of servers, Swarm does the job with far less to maintain.
What is Dokploy?
An open-source platform you install on your own servers, similar to Heroku or Vercel. It connects to your GitHub repositories, builds and deploys the apps, runs databases, and handles domains and TLS certificates through Traefik. It runs on Docker Swarm, so more capacity is one more worker.
How do preview deployments work?
When someone pushes a feature branch, Dokploy builds it and starts it on its own subdomain. Product owners and testers click through the feature before it is merged, and nobody has to wait for a shared staging server.
Why Cloudflare in front?
Cloudflare answers DNS, caches static files close to the visitor and filters attacks before they reach your servers, whose IP addresses stay hidden behind it. Redirects and caching rules live there too, instead of in each app.
Can you take over our existing setup?
Yes. I start with a review: what runs where, how a deploy works today, what happens when a server goes down and where the backups are. You get it in writing, with what to fix first.
What does it cost?
Pricing is on request: a fixed price or time and materials for projects, by the hour or as a monthly retainer for advisory. You get a written quote within 48 hours.