The Extant 2000 products, nine-plus separate apps, all run on a single VPS. Not for lack of budget, but because one well-organized box is easier to reason about than a fleet.

The layout

Each app is a container; Traefik routes them by subdomain; a shared Postgres backs the data; Let's Encrypt handles every cert. The whole suite lives in version-controlled compose files, so the box is reproducible.

Sharing one Postgres across nine apps is the decision people query most, and the answer is roles. Each application connects as its own database role that can touch only its own tables, so "shared server" does not mean "shared access". You get one thing to tune, one connection pool to watch, one backup to verify, and joins across products when you need them.

Isolation where it counts

"One box" doesn't mean "one blast radius." Untrusted or experimental workloads get their own network segments and egress rules, so a problem in one place can't wander into another. Prod apps, the media stack, and the retro lab share metal but sit in separate lanes.

Docker's default behaviour is the thing to fight here: every container on the same user-defined network can reach every other one, and the default bridge is worse. The lanes are separate networks, and a container joins exactly the ones it needs. Traefik is the only thing attached to more than a couple, because that is its job.

What actually bites

The honest failure mode of one box is not CPU, it's memory. A modern VPS has more cores than a small suite will ever saturate, but when memory runs out the kernel's OOM killer picks a victim by a score dominated by resident set size, which means it reaches for the largest process rather than the one that misbehaved. A runaway build can get your database killed. The mitigations are unglamorous: a memory limit on every service so a container hits its own ceiling before the host does, swap sized so you get slow instead of dead, and never running a heavy build on the box while it is serving.

The other one is that a single kernel is a single kernel. A reboot for a security patch is downtime for everything at once, and it needs a maintenance window rather than a shrug.

Operationally calm

One place to deploy, one to back up, one to look when something's off. Vertical beats horizontal until you outgrow the machine, and a modern VPS holds a lot before you do.

The least glamorous architecture decision I've made, and one of the best.