Platform maintenance: moving all services to an unprivileged container runtime Saturday 5th September 2026 19:44:00


As the final step of this week's security hardening, every DragonHive / derg.nz service is being moved from a root-level container runtime to an unprivileged one.

During this window each service restarts once. Expect short, intermittent outages: typically 1-5 minutes per service, up to ~10 minutes for GitLab, Mastodon, Nextcloud and Seafile. No data is modified, and the previous setup is kept intact for an instant rollback.

This entry stays open until the migration is complete and verified; progress updates follow below.

All 31 services were moved to the unprivileged container runtime and re-verified after the updater's first cycle (18 services re-created onto freshly pulled images, all healthy). Nothing was rolled back. From now on, feature upgrades of Mastodon, Seafile and Nextcloud will be announced on this page a day in advance, with a summary of what changes.

All 31 services have moved to the unprivileged runtime and pass their health checks. The automatic updater now runs there too; its first cycle (20:50) re-creates a number of containers onto freshly pulled copies of the same images, so expect one more short restart per service. This entry closes once that round is verified.

Progress: 27 of 31 services have moved and are verified healthy (all sites, games, calling, streaming, Matrix). Remaining: GitLab, Nextcloud, Seafile and Mastodon, which move one at a time as their images finish copying; each will be unavailable for roughly 3-10 minutes during its move.

Migration window started. The reverse proxy moves first, then each service in turn; a service is unreachable from the moment its old copy stops until its new copy is up (usually 1-3 minutes).

Related Mastodon account