Per-stage env var overrides with encryption for secrets. Volume mounts with shared/isolated modes (isolated appends /{stage}-{tag}/ to source path). Store CRUD, API endpoints, and frontend editors for both. Env merge during deploy.
Phase 3: Docker Engine API wrapper — pull/inspect images, container lifecycle (create/start/stop/remove/restart), network management, label-based container tracking, deterministic naming. Phase 4: Nginx Proxy Manager API client — JWT auth with auto-refresh, CRUD for proxy hosts, domain-based host lookup.