Docker's built-in orchestrator · services · stacks · overlay networks · secrets · verified against Docker Engine (2026)

Docker Swarm cheat sheet

Swarm mode is built into the Docker Engine — no extra install. Turn a set of Docker hosts into one cluster with docker swarm init, then run services (replicated or global) across it, connect them over overlay networks, deploy multi-service apps from a Compose file as a stack, and ship config & secrets securely. The built-in routing mesh load-balances a published port across every node. It's the simplest path to multi-host orchestration when Kubernetes is more than you need. Uses the same Docker CLI you already know.

cluster & nodes services networks & routing stacks · secrets · configs ops & ecosystem gotcha most common

Verified 2026-08-31 against the official docs at docs.docker.com/engine/swarm. Swarm ships inside the Docker Engine (CE) — docker swarm/node/service/stack/secret/config are core CLI commands. See also the companion Docker, Docker Compose & Dockerfile sheets.

Outline

Init a swarm, join nodes, then declare services (or deploy a stack). Overlay networks connect them; the routing mesh publishes ports; secrets/configs inject data safely.

Cluster & services

  1. 1Init & join
  2. 2Managing nodes
  3. 3Services
  4. 4Scale & update

Networking & stacks

  1. 5Overlay networks
  2. 6Routing mesh & ports
  3. 7Stacks
  4. 8Secrets & configs

Ops & ecosystem

  1. 9Placement & constraints
  2. 10Rolling updates & health
  3. 11Inspect & debug
  4. 12Swarm vs Kubernetes

Cluster & Services

Form the cluster, manage nodes, and run replicated services.

1Init & joinform the swarm
2Managing nodesmanagers & workers
3Servicesthe unit of work
4Scale & updatechange desired state

Networking & Stacks

Connect services across hosts and deploy whole apps from Compose.

5Overlay networksmulti-host
6Routing mesh & portspublish
7StacksCompose in prod
8Secrets & configsinject data safely

Ops & Ecosystem

Place tasks, roll out safely, debug, and know when to reach for Kubernetes.

9Placement & constraintswhere tasks run
10Rolling updates & healthsafe deploys
11Inspect & debugwhat's wrong
12Swarm vs Kuberneteschoosing

Worth memorizing

swarm init --advertise-addrfirst node = manager
swarm join --token ...:2377add workers
3 or 5 managersodd count for Raft quorum
service create --replicas / --mode globalthe unit of work
service scale / update / rollbackchange & revert desired state
network create -d overlaycross-node; DNS by service name
routing meshpublished port on every node, LB'd
stack deploy -c compose.ymluses the deploy: key; no build:
secret create -> /run/secrets/encrypted, in-memory; immutable
--constraint node.labels...control placement
--update-parallelism/-delayrolling updates + rollback
service ps --no-truncsee the real failure reason