Go to file
Elvis Pranskevichus 11a9bb6ce7
drivers/exec: Fix handling of capabilities for unprivileged tasks (#16643)
Currently, the `exec` driver is only setting the Bounding set, which is
not sufficient to actually enable the requisite capabilities for the
task process.  In order for the capabilities to survive `execve`
performed by libcontainer, the `Permitted`, `Inheritable`, and `Ambient`
sets must also be set.

Per CAPABILITIES (7):

> Ambient: This is a set of capabilities that are preserved across an
> execve(2) of a program that is not privileged.  The ambient capability
> set obeys the invariant that no capability can ever be ambient if it
> is not both permitted and inheritable.
2023-03-28 12:12:55 -04:00
.changelog drivers/exec: Fix handling of capabilities for unprivileged tasks (#16643) 2023-03-28 12:12:55 -04:00
.circleci build: update from go1.20.1 to go1.20.2 (#16427) 2023-03-13 09:47:07 -07:00
.github CI: delete test-link-rewrites.yml (#16354) 2023-03-06 15:41:01 -05:00
.release ci: send notification when prepare is complete (#16627) 2023-03-23 17:34:45 -04:00
.semgrep Accept Workload Identities for Client RPCs (#16254) 2023-02-27 10:17:47 -08:00
.tours Make number of scheduler workers reloadable (#11593) 2022-01-06 11:56:13 -05:00
acl acl: prevent privilege escalation via workload identity 2023-03-13 11:13:27 -04:00
api client/fingerprint: correctly fingerprint E/P cores of Apple Silicon chips (#16672) 2023-03-28 08:27:58 -05:00
ci tests: add functionality to skip a test if it's not running in CI and not with root user (#16222) 2023-03-02 13:38:27 -05:00
client client/fingerprint: correctly fingerprint E/P cores of Apple Silicon chips (#16672) 2023-03-28 08:27:58 -05:00
command cli: job restart command (#16278) 2023-03-23 18:28:26 -04:00
contributing contrib: architecture guide to the drainer (#16569) 2023-03-21 09:17:24 -04:00
demo Update ioutil library references to os and io respectively for e2e helper nomad (#16332) 2023-03-08 09:39:03 -06:00
dev dev: remove use of cfssl and use Nomad CLI for TLS certs. (#16145) 2023-03-20 17:06:15 +01:00
drivers drivers/exec: Fix handling of capabilities for unprivileged tasks (#16643) 2023-03-28 12:12:55 -04:00
e2e e2e: sleep to ensure logs are picked up (#16596) 2023-03-21 14:10:50 -07:00
helper client/fingerprint: correctly fingerprint E/P cores of Apple Silicon chips (#16672) 2023-03-28 08:27:58 -05:00
integrations spelling: registrations 2018-03-11 18:40:53 +00:00
internal/testing/apitests api: add OIDC HTTP API endpoints and SDK. 2023-01-13 13:15:58 +00:00
jobspec Add option to expose workload token to task (#15755) 2023-02-02 10:59:14 -08:00
jobspec2 Update ioutil library references to os and io respectively for e2e helper nomad (#16332) 2023-03-08 09:39:03 -06:00
lib deps: upgrade to hashicorp/golang-lru/v2 (#16085) 2023-02-08 15:20:33 -06:00
nomad Multiple instances of a periodic job are run simultaneously, when prohibit_overlap is true (#16583) 2023-03-27 17:25:05 +02:00
plugins plugin: add missing fields to `TaskConfig` (#16434) 2023-03-13 15:58:16 -04:00
scheduler scheduler: fix reconciliation of reconnecting allocs (#16609) 2023-03-24 19:38:31 -04:00
scripts dev: make cni, consul, dev, docker, and vault scripts Lima compat. (#16689) 2023-03-28 16:21:14 +01:00
terraform terraform: update installed versions of HashiCorp tools. (#13635) 2022-07-07 16:12:19 +02:00
testutil client/metadata: fix crasher caused by AllowStale = false (#16549) 2023-03-20 16:32:32 -07:00
tools chore: Convert assets from bindatafs to go embeds (#16066) 2023-02-10 12:02:29 -05:00
ui [ui] Copyable server and client attribute values (#16548) 2023-03-22 15:05:01 -04:00
version Post 1.5.2 release (#16614) 2023-03-22 14:23:38 -07:00
website docs: add notes about keyring to snapshot restore (#16663) 2023-03-28 08:31:01 -04:00
.git-blame-ignore-revs ignore b0a20b4dc965a38b0c843f47c16685ccad7439da (#13648) 2022-07-07 15:16:18 -07:00
.gitattributes Remove invalid gitattributes 2018-02-14 14:47:43 -08:00
.gitignore git: ignore .fleet directory (#16144) 2023-02-13 07:39:30 -06:00
.go-version build: update from go1.20.1 to go1.20.2 (#16427) 2023-03-13 09:47:07 -07:00
.golangci.yml build: update linters (#15063) 2022-10-27 15:02:30 -05:00
.semgrepignore build: disable semgrep on structs.go for now 2022-02-01 10:09:49 -06:00
CHANGELOG.md Post 1.5.2 release (#16614) 2023-03-22 14:23:38 -07:00
CODEOWNERS ensure engineering has merge authority on build pipeline (#15350) 2022-11-21 14:30:02 -05:00
GNUmakefile Post 1.5.2 release (#16614) 2023-03-22 14:23:38 -07:00
LICENSE [COMPLIANCE] Update MPL 2.0 LICENSE (#14884) 2022-10-13 08:43:12 -04:00
README.md read: fix incorrect link to ref. arch. (#16103) 2023-02-09 11:52:31 +01:00
Vagrantfile dev: make cni, consul, dev, docker, and vault scripts Lima compat. (#16689) 2023-03-28 16:21:14 +01:00
build_linux_arm.go gofmt all the files 2021-10-01 10:14:28 -04:00
go.mod client/fingerprint: correctly fingerprint E/P cores of Apple Silicon chips (#16672) 2023-03-28 08:27:58 -05:00
go.sum client/fingerprint: correctly fingerprint E/P cores of Apple Silicon chips (#16672) 2023-03-28 08:27:58 -05:00
main.go main: remove deprecated uses of rand.Seed (#16074) 2023-02-07 09:19:38 -06:00
main_test.go

README.md

Nomad License: MPL 2.0 Discuss

HashiCorp Nomad logo

Nomad is a simple and flexible workload orchestrator to deploy and manage containers (docker, podman), non-containerized applications (executable, Java), and virtual machines (qemu) across on-prem and clouds at scale.

Nomad is supported on Linux, Windows, and macOS. A commercial version of Nomad, Nomad Enterprise, is also available.

Nomad provides several key features:

  • Deploy Containers and Legacy Applications: Nomads flexibility as an orchestrator enables an organization to run containers, legacy, and batch applications together on the same infrastructure. Nomad brings core orchestration benefits to legacy applications without needing to containerize via pluggable task drivers.

  • Simple & Reliable: Nomad runs as a single binary and is entirely self contained - combining resource management and scheduling into a single system. Nomad does not require any external services for storage or coordination. Nomad automatically handles application, node, and driver failures. Nomad is distributed and resilient, using leader election and state replication to provide high availability in the event of failures.

  • Device Plugins & GPU Support: Nomad offers built-in support for GPU workloads such as machine learning (ML) and artificial intelligence (AI). Nomad uses device plugins to automatically detect and utilize resources from hardware devices such as GPU, FPGAs, and TPUs.

  • Federation for Multi-Region, Multi-Cloud: Nomad was designed to support infrastructure at a global scale. Nomad supports federation out-of-the-box and can deploy applications across multiple regions and clouds.

  • Proven Scalability: Nomad is optimistically concurrent, which increases throughput and reduces latency for workloads. Nomad has been proven to scale to clusters of 10K+ nodes in real-world production environments.

  • HashiCorp Ecosystem: Nomad integrates seamlessly with Terraform, Consul, Vault for provisioning, service discovery, and secrets management.

Quick Start

Testing

See Learn: Getting Started for instructions on setting up a local Nomad cluster for non-production use.

Optionally, find Terraform manifests for bringing up a development Nomad cluster on a public cloud in the terraform directory.

Production

See Learn: Nomad Reference Architecture for recommended practices and a reference architecture for production deployments.

Documentation

Full, comprehensive documentation is available on the Nomad website: https://www.nomadproject.io/docs

Guides are available on HashiCorp Learn.

Contributing

See the contributing directory for more developer documentation.