reverse-proxy runs Swarm mode:global (one instance per node), all writing to the same CephFS file. This wrapper uses a shared flock + shared logrotate state file (both also on the CephFS mount) so cron on docker-1/2/3 can run independently without racing or double-rotating.