Concepts

Groups

Divide a codebase into shared networks, env, and secrets.

A group is machine-local organisation plus a shared network and shared env/secrets defaults. It is how a codebase gets divided into pieces a team can own on its own.

ant nest groups list                              # list groups
ant nest groups create backend --domain example.com   # create with a base domain
ant nest groups add backend api worker            # add projects to a group
ant nest groups remove worker                     # remove a project
ant nest groups rename backend services
ant nest groups network backend                   # show/set the shared docker network
ant nest groups delete backend --yes

Group env and secret defaults are edited in ~/.ant/config.json (or the dashboard's group page); the CLI exposes the network and domains.

What a group provides

  • a shared docker network its projects join, so services reach each other by name;
  • env and secret defaults inherited by every project in the group;
  • a natural boundary for ownership: a group is the unit a team can own.

Groups belong to a machine

A group is defined on one machine: the nest its projects deploy to, and its shared docker network lives there:

ant nest groups create backend --target-machine prod
ant nest groups network backend --name backend-net
ant nest groups domains backend prod.example.com

create records the machine the group belongs to (--target-machine); every other group command resolves the group by its globally-unique name, so it does not take --machine.

Names are globally unique across machines, so the same logical team on two machines needs two groups (backend-local, backend-prod). A project joins its group's network only when the group is defined on the machine the project targets: a project with machine: prod whose group exists only on local keeps the group's env and secrets defaults but not the network, because that network does not exist on prod.

Project directories

In schema v2 a project's location is a fact about the machine it lives on. The machine lists the directories it scans for projects, and a group can list extra directories for its own members:

machines.local.project_dirs                 = ["/home/me/code"]
machines.local.groups.backend.project_dirs  = ["/home/me/code/api", "/home/me/code/worker"]

A project joins the group with group: backend in its ant.yaml; the group's directories are scanned on top of the machine's own.

Opting out of the network

A project can keep the group's env but decline its network:

# ant.yaml
deploy:
  use_group_network: false

The project page in the dashboard lists every network a project uses (its own, the group's inherited one, and the compose file's) with driver, subnet, and whether it is external.

Copyright © 2026