Brownsmith Dynamics
ServicesProductsCoursesToolsCompanyBlogsWhy UsPricingFAQsQuizContact
  1. Home
  2. From Repository To Production
  3. Compose Environment Files And Secrets
  1. Home
  2. Courses
  3. Self Hosting Open Source Applications
  4. From Repository To Production
  5. Compose Environment Files And Secrets

Brownsmith Dynamics

AI systems, workflow software, websites, automation, and search visibility for small teams from Dehradun.

ContactProductsServicesPricingCoursesWhy UsFAQsToolsBlogsQuiz

Sitemap

HomeSoftware that works with the business.ProductsConfigurable product bases for real operations.CoursesTechnical decisions for founders who do not need to become engineers.All ServicesAI, software, automation, web, data, visibility, and modernisation services.ContactBook an initial workflow and build scoping call.
Expand to See the Full SitemapCollapse the Full Sitemap

Core Pages

CompanyBrownsmith Dynamics company and registered business details.Why UsModern systems should reduce friction, not add another process.PricingA transparent framework for software-development pricing.Brownsmith Dynamics MCPPublic documentation for a read-only MCP currently in private testing.FAQsFrequently Asked QuestionsToolsOpen-source tools for practical software teams.Tools DataOpen tools data and a shareable shortlist builder.QuizDecide whether to self-build, prototype, or get help.

Services

AI ImplementationAI That Fits the Work.AI-Native SystemsMake Existing Systems AI-Accessible.Web DevelopmentWebsites That Explain the Business.Business AutomationRemove the Work That Keeps Repeating.Custom SoftwareSoftware Around the Business.Ghost DevelopmentYour Product. Built Behind the Scenes.Legacy ModernisationModernise Without Unnecessary Replacement.Data and ReportingMake Business Data Easier to Use.SEO, AEO and GEOMake the Offer Easier to Understand.Performance MarketingPerformance Marketing Guided by Real Data.Technical WritingClear Writing for Complex Work.

Founder Learning

Course BundleCourses, modules, exercises, and knowledge checks for technical decisions.Building an AI-Native BusinessA business-level course on structured knowledge, models, agents, tools, MCP, permissions, legacy systems, and an incremental AI adoption roadmap. No advanced programming background is required.MVP Building for FoundersTurn an idea into a product that can be built, tested, and evaluated without allowing the first version to become the entire company.Product and Interface DesignDesign an MVP that users can understand, navigate, and trust before spending time polishing its visual details.Frontend for FoundersUnderstand the part of the product users see, the decisions that shape it, and the warning signs of a fragile implementation.Backend for FoundersUnderstand how an application processes rules, protects actions, communicates with services, and responds when something fails.Databases for FoundersLearn how product data is structured, protected, changed, exported, and recovered.Infrastructure and DeploymentUnderstand where software runs, how it reaches users, what it costs, and who is responsible when it stops working.AI-Assisted Product BuildingUse conversational AI, vibe-coding platforms, coding agents, skills, and agent systems as parts of a controlled product-development workflow.Testing and Quality AssuranceTest interfaces, APIs, workflows, permissions, limits, and failure cases before users discover the problems.Security, Ownership, and OperationsProtect the product, retain control of critical accounts, and prepare the system to be maintained after launch.Self-Hosting Open-Source ApplicationsMove from a maintained open-source repository to a secure, containerised VPS deployment that can be operated, updated, backed up, and recovered.GlossaryTechnical terms explained for product and business decisions.

AI-Native Systems

AI-Native Business SystemsBrownsmith Dynamics documents, structures, and connects existing business systems so approved AI products and automated workflows can interact with them more reliably.Brownsmith Dynamics MCPExplore the privately tested read-only MCP, resources, and provider guidance.Public AI DocumentationAuthoritative public business information for AI systems.Structured Business DataMachine-readable public services, products, courses, and contacts.llms.txtMachine-friendly website and public documentation map.

Product Pages

Fonte UIA developing product concept designed to become the source interface for day-to-day work, turning communication from email, WhatsApp, and Microsoft Teams into trackable work on one Kanban board.Private Agent WorkspaceA familiar private chat where every person can have a personal assistant, every group can have a separate shared helper, and specialists can support planning, research, writing, support, and software work.Web Conversation EngineA Website That Answers Like the Business.Private Model InfrastructureControl the Stack Before Scaling the Use Cases.Workflow Automation HubMove Repeat Work Out of Manual Loops.Data Intelligence WorkbenchTurn Messy Business Data Into Decisions.Growth Intelligence PlatformMake Organic Growth Less Random.Workforce Intelligence SuiteGive HR a System for the Work Between Forms.Contract & Compliance DeskMake Document Review Faster and More Traceable.Industrial Operations PlatformGive Operations Teams Earlier Signals.Healthcare Operations WorkbenchReduce Administrative Drag Across Care Teams.Learning Operations PlatformGive Educators More Time for Students.Security Operations ConsoleHelp Analysts Find the Events That Matter.Property Intelligence SuiteBring Property Data, Leases, and Tenant Work Into One View.Commerce Intelligence PlatformMake the Catalogue Easier to Run and Easier to Buy From.Prompt ComposerReview, Format, and Reuse Prompts Where You Write.

Contact and Discovery

EmailEmail Brownsmith Dynamics about a practical build.XML SitemapMachine-readable route map for crawlers.

Core Pages

CompanyBrownsmith Dynamics company and registered business details.HomeSoftware that works with the business.Why UsModern systems should reduce friction, not add another process.PricingA transparent framework for software-development pricing.ProductsConfigurable product bases for real operations.CoursesTechnical decisions for founders who do not need to become engineers.Brownsmith Dynamics MCPPublic documentation for a read-only MCP currently in private testing.FAQsFrequently Asked QuestionsToolsOpen-source tools for practical software teams.Tools DataOpen tools data and a shareable shortlist builder.QuizDecide whether to self-build, prototype, or get help.

Services

All ServicesAI, software, automation, web, data, visibility, and modernisation services.AI ImplementationAI That Fits the Work.AI-Native SystemsMake Existing Systems AI-Accessible.Web DevelopmentWebsites That Explain the Business.Business AutomationRemove the Work That Keeps Repeating.Custom SoftwareSoftware Around the Business.Ghost DevelopmentYour Product. Built Behind the Scenes.Legacy ModernisationModernise Without Unnecessary Replacement.Data and ReportingMake Business Data Easier to Use.SEO, AEO and GEOMake the Offer Easier to Understand.Performance MarketingPerformance Marketing Guided by Real Data.Technical WritingClear Writing for Complex Work.

Founder Learning

Course BundleCourses, modules, exercises, and knowledge checks for technical decisions.Building an AI-Native BusinessA business-level course on structured knowledge, models, agents, tools, MCP, permissions, legacy systems, and an incremental AI adoption roadmap. No advanced programming background is required.MVP Building for FoundersTurn an idea into a product that can be built, tested, and evaluated without allowing the first version to become the entire company.Product and Interface DesignDesign an MVP that users can understand, navigate, and trust before spending time polishing its visual details.Frontend for FoundersUnderstand the part of the product users see, the decisions that shape it, and the warning signs of a fragile implementation.Backend for FoundersUnderstand how an application processes rules, protects actions, communicates with services, and responds when something fails.Databases for FoundersLearn how product data is structured, protected, changed, exported, and recovered.Infrastructure and DeploymentUnderstand where software runs, how it reaches users, what it costs, and who is responsible when it stops working.AI-Assisted Product BuildingUse conversational AI, vibe-coding platforms, coding agents, skills, and agent systems as parts of a controlled product-development workflow.Testing and Quality AssuranceTest interfaces, APIs, workflows, permissions, limits, and failure cases before users discover the problems.Security, Ownership, and OperationsProtect the product, retain control of critical accounts, and prepare the system to be maintained after launch.Self-Hosting Open-Source ApplicationsMove from a maintained open-source repository to a secure, containerised VPS deployment that can be operated, updated, backed up, and recovered.GlossaryTechnical terms explained for product and business decisions.

AI-Native Systems

AI-Native Business SystemsBrownsmith Dynamics documents, structures, and connects existing business systems so approved AI products and automated workflows can interact with them more reliably.Brownsmith Dynamics MCPExplore the privately tested read-only MCP, resources, and provider guidance.Public AI DocumentationAuthoritative public business information for AI systems.Structured Business DataMachine-readable public services, products, courses, and contacts.llms.txtMachine-friendly website and public documentation map.

Product Pages

Fonte UIA developing product concept designed to become the source interface for day-to-day work, turning communication from email, WhatsApp, and Microsoft Teams into trackable work on one Kanban board.Private Agent WorkspaceA familiar private chat where every person can have a personal assistant, every group can have a separate shared helper, and specialists can support planning, research, writing, support, and software work.Web Conversation EngineA Website That Answers Like the Business.Private Model InfrastructureControl the Stack Before Scaling the Use Cases.Workflow Automation HubMove Repeat Work Out of Manual Loops.Data Intelligence WorkbenchTurn Messy Business Data Into Decisions.Growth Intelligence PlatformMake Organic Growth Less Random.Workforce Intelligence SuiteGive HR a System for the Work Between Forms.Contract & Compliance DeskMake Document Review Faster and More Traceable.Industrial Operations PlatformGive Operations Teams Earlier Signals.Healthcare Operations WorkbenchReduce Administrative Drag Across Care Teams.Learning Operations PlatformGive Educators More Time for Students.Security Operations ConsoleHelp Analysts Find the Events That Matter.Property Intelligence SuiteBring Property Data, Leases, and Tenant Work Into One View.Commerce Intelligence PlatformMake the Catalogue Easier to Run and Easier to Buy From.Prompt ComposerReview, Format, and Reuse Prompts Where You Write.

Contact and Discovery

ContactBook an initial workflow and build scoping call.EmailEmail Brownsmith Dynamics about a practical build.XML SitemapMachine-readable route map for crawlers.
Course Navigation
Self-Hosting Open-Source Applications
  1. 1.Self-Hosting Economics and Responsibility
  2. 2.Preparing a VPS, DNS, Ports, and TLS
  3. 3.Git and Repository Preparation
  4. 4.Building and Inspecting a Docker Image
  5. 5.Compose, Environment Files, and Secrets
  6. 6.Deploying with Coolify or Dokploy
  7. 7.OAuth and API Key Management
  8. 8.AI APIs and MCP Services
  9. 9.Private Access with Tailscale
  10. 10.Production Deployment and Recovery Capstone
Self-Hosting Open-Source Applications
  1. 1.Self-Hosting Economics and Responsibility
  2. 2.Preparing a VPS, DNS, Ports, and TLS
  3. 3.Git and Repository Preparation
  4. 4.Building and Inspecting a Docker Image
  5. 5.Compose, Environment Files, and Secrets
  6. 6.Deploying with Coolify or Dokploy
  7. 7.OAuth and API Key Management
  8. 8.AI APIs and MCP Services
  9. 9.Private Access with Tailscale
  10. 10.Production Deployment and Recovery Capstone
  1. Courses
  2. /
  3. Self-Hosting Open-Source Applications
  4. /
  5. From Repository to Production
  6. /
  7. Compose, Environment Files, and Secrets
Self-Hosting Open-Source ApplicationsFrom Repository to Production

Compose, Environment Files, and Secrets

Compose should define services, pinned images, private networks, volumes, health checks, and non-secret defaults. Real secrets belong outside Git and should be injected at runtime through the strongest mechanism the platform supports.

15 minute lessonUpdated July 30, 2026intermediate

What You Will Be Able to Decide

  • Explain the role of compose, environment files, and secrets in a self-hosted system.
  • Apply the procedure to a real open-source deployment.
  • Recognise unsafe defaults and verify the resulting control.
  • Record enough evidence for another operator to repeat or recover the work.

Most useful self-hosted applications are systems rather than single processes. An application, database, queue, and reverse proxy may have different lifecycles but still need one understandable deployment definition.

Docker Compose expresses those relationships in YAML. It can create private networks and named volumes, pass configuration, order startup dependencies, and define health checks.

An environment file is convenient, but convenience is not encryption. Its filesystem permissions, backup path, platform visibility, and Git exclusions still matter.

Technical term

Runtime secret

Sensitive data made available to a running service without baking it into the image or committing it to source control.

It is a key issued when a worker starts a shift, not a key photographed into the construction plans.

The Working Model

Compose interpolation can read values from a local `.env`, while a service-level `env_file` passes variables into the container. Those are different stages. Use `docker compose config` to inspect the resolved model, but avoid exposing its output when it includes secret values.

Put databases and supporting services on a private network. Use named volumes for durable data and document exactly what each volume contains. A volume is persistence, not a backup: deletion, corruption, or host loss can still remove it.

Where the deployment platform supports secret files or an external secret manager, prefer them for high-value credentials. Always restrict file permissions and rotate any credential that has entered Git history, logs, screenshots, or shell history.

Implementation Procedure

  1. Copy `.env.example` to `.env`, generate unique values, restrict access, and confirm `.env` is ignored by Git.
  2. Pin each service image and define a restart policy.
  3. Create a private application network and publish only the web entry point.
  4. Declare named volumes for databases, uploads, and other durable paths.
  5. Resolve and review the Compose model, start it, inspect health, then recreate it to test persistence.
services:
  app:
    image: ghcr.io/example/project:1.4.2
    restart: unless-stopped
    env_file: .env
    ports:
      - "127.0.0.1:8080:3000"
    volumes:
      - app-data:/data
    networks: [private]

volumes:
  app-data:

networks:
  private:
    internal: true

Knowledge Check

What is the difference between persistence and backup?

Controlled Practice and Fragile Practice

Controlled Practice

The deployment stays explainable, constrained, and recoverable.

  • Commit `.env.example`; ignore and protect `.env`.
  • Name every persistent volume and include it in the recovery plan.
  • Review the fully resolved Compose model before deployment.

Fragile Practice

Convenient shortcuts create hidden exposure or an unrecoverable dependency.

  • Assuming a named volume is automatically backed up.
  • Using the same default password in staging and production.
  • Publishing every service port to make connectivity easier.

Exercise

Apply the Boundary

Select the production-safe characteristics of a Compose deployment.

Select all answers that apply

Verification and Recovery Evidence

  • `docker compose ps` reports the intended services and health states.
  • The database cannot be reached directly from the public internet.
  • A fresh container can use the existing volume and a restore test can rebuild that volume from backup.

Knowledge Check

What should happen after a secret is committed to Git?

Warning Signs

  • The Compose file uses default credentials shown in upstream examples.
  • No one knows which volume contains uploads or the primary database.
  • Resolved configuration is pasted into public support channels.

Questions to Ask a Consultant

  • Which configuration is safe to commit and which values require rotation?
  • Can every named volume be mapped to a backup and restore procedure?
  • Which services genuinely need to communicate with each other?

Exercise

Founder Decision Note

Record the decision, its current constraint, recommended option, main reason, primary risk, and the condition that would make you revisit it.

Key takeaway

Key Takeaway

Compose turns architecture into a reviewable file. Use that visibility to constrain networks, declare persistence, and keep real secrets out of source history.

Apply This Decision to Your Product.

Understanding a technical concept is useful. Applying it still depends on your product, users, budget, data, and operating constraints.

Brownsmith Dynamics can review an MVP scope, technical proposal, architecture, deployment plan, AI-assisted workflow, or existing application.

For corrections, questions, and suggested improvements to this lesson, contact us directly.

Book a Technical Consultation Ask a Question or Suggest an Improvement
Previous LessonBuilding and Inspecting a Docker ImageNext Lesson Deploying with Coolify or Dokploy

Related Lessons

  • Building and Inspecting a Docker Image
  • Deploying with Coolify or Dokploy

On This Lesson

  1. Runtime Secret
  2. The Working Model
  3. Implementation Procedure
  4. Knowledge Check
  5. Controlled Practice and Fragile Practice
  6. Apply the Boundary
  7. Verification and Recovery Evidence
  8. Knowledge Check
  9. Warning Signs
  10. Questions to Ask
  11. Key Takeaway