# ADR 0001 — Single bare-metal host, Docker Compose per customer **Status:** Accepted ## Context Small hosting business, modest site count, ZFS-based backup strategy. Options ranged from a single host to a multi-host orchestrated fleet (Swarm/Nomad/k8s) or cloud VMs. ## Decision Run everything on **one bare-metal host**, using **one Docker Compose project per customer/site**. No orchestrator. Host configured with Ansible. ## Consequences - ✅ Simplest possible operational model; ZFS lives directly on local disks (best snapshot/`send` story, no network-storage complications). - ✅ Compose-per-customer maps 1:1 to the isolation and backup boundary. - ✅ No control-plane overhead (no etcd, no scheduler). - ❌ No built-in HA/failover; the host is a single point of failure — mitigated by disciplined offsite backups and a documented rebuild/restore drill. - ❌ Vertical scaling only. If site count outgrows one box, revisit with a superseding ADR (Swarm/Nomad, ZFS locality becomes the hard problem).