Skip to content

Reboot, roll back or restart, with a swipe and Face ID

A droplet power action is a request to DigitalOcean to change a droplet's power state: a shutdown or reboot is a graceful attempt, while a power off or power cycle is the equivalent of pulling the plug or pressing reset. Duskwatch is an independent iPhone app for DigitalOcean, in development; it runs 13 actions on droplets, App Platform apps and databases, each behind one confirmation sheet, a swipe for anything disruptive, and Face ID.

Updated

The 13 actions

The list is the set of things worth doing from a phone at night: restore service, contain damage, or take a safety copy. Anything that creates, resizes or deletes stays on the laptop.

Every action, the resource it applies to, and how it is confirmed
ResourceActionArmed with
DropletPower onTap
DropletShut downSwipe
DropletPower offSwipe
DropletRebootSwipe
DropletPower cycleSwipe
DropletTake snapshotTap
AppRedeploy, optionally with a forced rebuildTap
AppRoll backSwipe
AppCommit the rollbackTap
AppRevert the rollbackSwipe
AppCancel a deploymentTap
AppRestartTap
DatabaseAdd my IP to trusted sourcesTap

Every row then asks for Face ID or your passcode. "Add my IP" is the one action that needs a lookup outside DigitalOcean: the app asks the Duskwatch server for your public IPv4 address, which that server neither logs nor stores, or you type one in; then it adds the address to the cluster's trusted sources.

One sheet names the action, the resource and the team

Before anything runs, one confirmation sheet says exactly what will happen, to what, and where. The team chip matters most when you look after several teams: "in acme-prod" is the line that stops you rebooting a client's web-01 instead of your own.

The confirmation sheet for a reboot

Reboot web-01

in acme-prod

Restarts web-01 cleanly. Its services are down until it's back, usually a minute or two.

Swipe to reboot web-01

You'll confirm with Face ID.

A swipe for anything disruptive, then Face ID every time

A button can be hit by a thumb reaching for something else. A swipe across a track cannot. Shut down, power off, reboot, power cycle, roll back and revert rollback all use a swipe, and the label always ends with the resource name: "Swipe to roll back api-prod". There is no setting to turn the swipe off.

Face ID or your passcode follows every action, routine or not, right before the request goes to DigitalOcean. The request goes straight from your iPhone to DigitalOcean; the alert server never runs an action and cannot, because its permission can only read.

Shut down, power off, reboot or power cycle: which to use

Start gentle. A shutdown or reboot lets the operating system close files and stop services. Use power off or power cycle when the droplet no longer answers, and know that it is the same as cutting power to a server.

Roll back, then commit or revert

When a release breaks api-prod, rolling back to the last good deployment is usually the fastest way back to a working app. A rollback is a state you leave on purpose: commit it to keep the old version and resume deploys, or revert it once the fix is ready. Until then, the app shows "Pinned to a rollback: pushes won't deploy", so a quiet failure to ship does not surprise you the next day.

When actions are off

  • Offline: actions are disabled until the app can reach DigitalOcean, so nothing queues up to run later.
  • Without the permission: sign-in asks only to view. Actions need "Enable actions", a separate permission you approve on DigitalOcean's page. How sign-in works.
  • Never deletes: there is no destroy, delete or resize anywhere in the app.

What Duskwatch doesn't do here

  • No deleting, destroying or resizing droplets, apps or databases.
  • No creating resources, and no editing firewalls, DNS or app specs.
  • No actions on Kubernetes, load balancers, volumes or Spaces.
  • No scheduled or automatic actions: every action is yours, confirmed in the moment.
  • No actions run by a server: they go from your iPhone to DigitalOcean.

Questions

  • Can I reboot a droplet from my iPhone?

    Yes. Open the droplet, choose Reboot, check the sheet that names web-01 and its team, swipe to reboot, then confirm with Face ID.

  • What is the difference between shut down, power off, reboot and power cycle?

    Shut down and reboot are graceful, like running the command on the droplet. Power off cuts the power and power cycle presses reset, so use them when the droplet no longer responds. A powered-off droplet is still billed.

  • Why a swipe instead of a button?

    A swipe cannot be triggered by a stray tap, so it guards the disruptive actions: shut down, power off, reboot, power cycle, roll back and revert rollback. Face ID follows every action.

  • Can I delete anything?

    No. There are no delete, destroy or resize actions in Duskwatch; those stay in DigitalOcean's control panel.

  • Does your server run the action?

    No. The request goes from your iPhone straight to DigitalOcean, using a permission that stays in your iPhone's Keychain.

  • What permission does it need?

    Sign-in asks only to view. To act, you turn on "Enable actions" and approve that permission on DigitalOcean's own page.

Duskwatch is in development. Join the waitlist to hear when it's on the App Store.

We'll email you once when Duskwatch is on the App Store. One-click unsubscribe. How we handle your data

Basic monitoring is free; alerts, most actions and advanced features are part of Duskwatch Pro.