Known limitations
Swarm is in beta. The CLI and API are stable in practice but not frozen. This page is the honest inventory of current boundaries; it is updated with every release.
Authentication and identity
Section titled “Authentication and identity”- Single role. All authenticated users are operators; no RBAC yet.
- Long-lived client certs (~1 year). Revocation is serial-list based and immediate; expiry is the backstop. No automatic renewal.
- No server↔agent auth beyond the SSH tunnel. Host keys are
verified with trust-on-first-use (
known_hosts); there is no per-agent secret.
Storage and deployment
Section titled “Storage and deployment”- Disk size applies at creation only — there is no live storage resize; grow the disk by provisioning a new VM.
- Env injects at container start, not image build. Secrets needed
inside Dockerfile RUN steps are a repo-side concern (BuildKit
RUN --mount=type=secret); build args would be baked into image history.
Networking
Section titled “Networking”- No east-west isolation on the private network — VMs on it form a trusted pool.
- Container HTTP proxy (v1): no WebSocket/HTTP upgrades, one
proxied port per container (server-wide), no per-request target
override, no
X-Forwarded-For(upstreams can’t see the client IP).
CLI surface
Section titled “CLI surface”- No first-class shell or port-forward commands — use
ssh root@<vm-ip> "docker exec -it <docker-id> bash"or the container HTTP proxy for HTTP services. - No CLI wrapper for the proxy — callers use curl or any HTTP client with the mTLS credentials.
Providers and platform
Section titled “Providers and platform”- UpCloud is the only cloud provider today. The provider layer is abstracted server-side, but no other provider is implemented.
- The agent is Linux-only (amd64/arm64); the CLI and server build for Linux, macOS, and Windows.
- Beta API stability: endpoints and payload shapes can change between beta releases; breaking changes are called out in the changelog.
History
Section titled “History”The changelog records what has changed and what was fixed in each release.