Reboot, roll back or restart, with a swipe and Face ID
A droplet power action is a request to DigitalOcean to change a droplet's power state: a shutdown or reboot is a graceful attempt, while a power off or power cycle is the equivalent of pulling the plug or pressing reset. Duskwatch is an independent iPhone app for DigitalOcean, in development; it runs 13 actions on droplets, App Platform apps and databases, each behind one confirmation sheet, a swipe for anything disruptive, and Face ID.
Updated
The 13 actions
The list is the set of things worth doing from a phone at night: restore service, contain damage, or take a safety copy. Anything that creates, resizes or deletes stays on the laptop.
| Resource | Action | Armed with |
|---|---|---|
| Droplet | Power on | Tap |
| Droplet | Shut down | Swipe |
| Droplet | Power off | Swipe |
| Droplet | Reboot | Swipe |
| Droplet | Power cycle | Swipe |
| Droplet | Take snapshot | Tap |
| App | Redeploy, optionally with a forced rebuild | Tap |
| App | Roll back | Swipe |
| App | Commit the rollback | Tap |
| App | Revert the rollback | Swipe |
| App | Cancel a deployment | Tap |
| App | Restart | Tap |
| Database | Add my IP to trusted sources | Tap |
Every row then asks for Face ID or your passcode. "Add my IP" is the one action that needs a lookup outside DigitalOcean: the app asks the Duskwatch server for your public IPv4 address, which that server neither logs nor stores, or you type one in; then it adds the address to the cluster's trusted sources.
One sheet names the action, the resource and the team
Before anything runs, one confirmation sheet says exactly what will happen, to what, and where. The team chip matters most when you look after several teams: "in acme-prod" is the line that stops you rebooting a client's web-01 instead of your own.
Reboot web-01
in acme-prod
Restarts web-01 cleanly. Its services are down until it's back, usually a minute or two.
Swipe to reboot web-01
You'll confirm with Face ID.
A swipe for anything disruptive, then Face ID every time
A button can be hit by a thumb reaching for something else. A swipe across a track cannot. Shut down, power off, reboot, power cycle, roll back and revert rollback all use a swipe, and the label always ends with the resource name: "Swipe to roll back api-prod". There is no setting to turn the swipe off.
Face ID or your passcode follows every action, routine or not, right before the request goes to DigitalOcean. The request goes straight from your iPhone to DigitalOcean; the alert server never runs an action and cannot, because its permission can only read.
Shut down, power off, reboot or power cycle: which to use
Start gentle. A shutdown or reboot lets the operating system close files and stop services. Use power off or power cycle when the droplet no longer answers, and know that it is the same as cutting power to a server.
A shutdown is an attempt to shut the droplet down gracefully, like running the shutdown command from its console.
doctl reference: droplet-action shutdown (external link), verified
A reboot is an attempt to reboot the droplet gracefully, like running the reboot command from its console.
doctl reference: droplet-action reboot (external link), verified
A power off is a hard shutdown, similar to cutting the power, and should only be used if a shutdown does not work. Powered-off droplets are still billable.
doctl reference: droplet-action power-off (external link), verified
A power cycle is similar to pushing the reset button on a physical machine.
doctl reference: droplet-action power-cycle (external link), verified
You can snapshot a running droplet, but DigitalOcean warns that doing so may degrade performance and compromise data consistency.
DigitalOcean docs: snapshot droplets (external link), verified
Roll back, then commit or revert
When a release breaks api-prod, rolling back to the last good deployment is usually the fastest way back to a working app. A rollback is a state you leave on purpose: commit it to keep the old version and resume deploys, or revert it once the fix is ready. Until then, the app shows "Pinned to a rollback: pushes won't deploy", so a quiet failure to ship does not surprise you the next day.
You can roll back to any of the ten most recent successful deployments; a rollback restores code, configuration and app spec but does not affect database data.
DigitalOcean docs: manage deployments (external link), verified
By default, a rollback pins the app to that deployment, and no new deployment is created, manually or by Auto Deploy on Push, until the rollback is committed or reverted.
DigitalOcean docs: create an app rollback (external link), verified
Reverting creates a new deployment from the latest app spec before the rollback and unpins the app.
DigitalOcean docs: revert an app rollback (external link), verified
When actions are off
- Offline: actions are disabled until the app can reach DigitalOcean, so nothing queues up to run later.
- Without the permission: sign-in asks only to view. Actions need "Enable actions", a separate permission you approve on DigitalOcean's page. How sign-in works.
- Never deletes: there is no destroy, delete or resize anywhere in the app.
What Duskwatch doesn't do here
- No deleting, destroying or resizing droplets, apps or databases.
- No creating resources, and no editing firewalls, DNS or app specs.
- No actions on Kubernetes, load balancers, volumes or Spaces.
- No scheduled or automatic actions: every action is yours, confirmed in the moment.
- No actions run by a server: they go from your iPhone to DigitalOcean.
Questions
Can I reboot a droplet from my iPhone?
Yes. Open the droplet, choose Reboot, check the sheet that names web-01 and its team, swipe to reboot, then confirm with Face ID.
What is the difference between shut down, power off, reboot and power cycle?
Shut down and reboot are graceful, like running the command on the droplet. Power off cuts the power and power cycle presses reset, so use them when the droplet no longer responds. A powered-off droplet is still billed.
Why a swipe instead of a button?
A swipe cannot be triggered by a stray tap, so it guards the disruptive actions: shut down, power off, reboot, power cycle, roll back and revert rollback. Face ID follows every action.
Can I delete anything?
No. There are no delete, destroy or resize actions in Duskwatch; those stay in DigitalOcean's control panel.
Does your server run the action?
No. The request goes from your iPhone straight to DigitalOcean, using a permission that stays in your iPhone's Keychain.
What permission does it need?
Sign-in asks only to view. To act, you turn on "Enable actions" and approve that permission on DigitalOcean's own page.