Go to file
Michael Schurter 3e50f72fad
core: merge reserved_ports into host_networks (#13651)
Fixes #13505

This fixes #13505 by treating reserved_ports like we treat a lot of jobspec settings: merging settings from more global stanzas (client.reserved.reserved_ports) "down" into more specific stanzas (client.host_networks[].reserved_ports).

As discussed in #13505 there are other options, and since it's totally broken right now we have some flexibility:

Treat overlapping reserved_ports on addresses as invalid and refuse to start agents. However, I'm not sure there's a cohesive model we want to publish right now since so much 0.9-0.12 compat code still exists! We would have to explain to folks that if their -network-interface and host_network addresses overlapped, they could only specify reserved_ports in one place or the other?! It gets ugly.
Use the global client.reserved.reserved_ports value as the default and treat host_network[].reserverd_ports as overrides. My first suggestion in the issue, but @groggemans made me realize the addresses on the agent's interface (as configured by -network-interface) may overlap with host_networks, so you'd need to remove the global reserved_ports from addresses shared with a shared network?! This seemed really confusing and subtle for users to me.
So I think "merging down" creates the most expressive yet understandable approach. I've played around with it a bit, and it doesn't seem too surprising. The only frustrating part is how difficult it is to observe the available addresses and ports on a node! However that's a job for another PR.
2022-07-12 14:40:25 -07:00
.changelog core: merge reserved_ports into host_networks (#13651) 2022-07-12 14:40:25 -07:00
.circleci build: bump circleci macos version 2022-07-05 09:38:00 -05:00
.github deps: run dependabot weekly (#13723) 2022-07-12 12:50:09 -07:00
.release fix hcl formatting 2022-07-08 14:07:18 -07:00
.semgrep workload identity (#13223) 2022-07-11 13:34:05 -04:00
.tours Make number of scheduler workers reloadable (#11593) 2022-01-06 11:56:13 -05:00
acl additional ACL Policy tests (#13464) 2022-07-11 13:34:06 -04:00
api build(deps): bump github.com/docker/go-units from 0.3.3 to 0.4.0 in /api (#11519) 2022-07-12 12:54:56 -07:00
ci ci: fixup task runner chroot test 2022-04-19 10:37:46 -05:00
client workload identity (#13223) 2022-07-11 13:34:05 -04:00
command core: merge reserved_ports into host_networks (#13651) 2022-07-12 14:40:25 -07:00
contributing build: update to go1.18.3 2022-07-01 10:12:56 -05:00
demo demo/docs: update demo of Kadalu CSI Plugin (#13610) 2022-07-06 10:24:34 -04:00
dev docs: swap master for main in Nomad repo 2021-03-08 14:26:31 -05:00
drivers driver/docker: Don't pull InfraImage if it exists (#13265) 2022-07-07 17:44:06 +02:00
e2e e2e: add terraform init commands to readme doc. (#13655) 2022-07-08 16:52:35 +02:00
helper Provide mock secure variables implementation (#12980) 2022-07-11 13:34:03 -04:00
integrations spelling: registrations 2018-03-11 18:40:53 +00:00
internal/testing/apitests ci: swap ci parallelization for unconstrained gomaxprocs 2022-03-15 12:58:52 -05:00
jobspec CSI: make plugin health_timeout configurable in csi_plugin stanza (#13340) 2022-06-14 10:04:16 -04:00
jobspec2 add filebase64 function (#11791) 2022-06-06 11:58:17 -04:00
lib client: enable support for cgroups v2 2022-03-23 11:35:27 -05:00
nomad core: merge reserved_ports into host_networks (#13651) 2022-07-12 14:40:25 -07:00
plugins ci: fixup task runner chroot test 2022-04-19 10:37:46 -05:00
scheduler core: merge reserved_ports into host_networks (#13651) 2022-07-12 14:40:25 -07:00
scripts ci: remove any other versions of Node installed (#13706) 2022-07-12 10:15:38 -04:00
terraform terraform: update installed versions of HashiCorp tools. (#13635) 2022-07-07 16:12:19 +02:00
testutil cli: correctly use and validate job with vault token set 2022-05-19 12:13:34 -05:00
tools ci: ensure package coverage of test-core 2022-04-14 19:04:06 -05:00
ui Remove namespace cache (#13679) 2022-07-11 18:06:18 -04:00
version Prepare for next release 2022-05-24 16:29:47 -04:00
website core: merge reserved_ports into host_networks (#13651) 2022-07-12 14:40:25 -07:00
.git-blame-ignore-revs ignore b0a20b4dc965a38b0c843f47c16685ccad7439da (#13648) 2022-07-07 15:16:18 -07:00
.gitattributes Remove invalid gitattributes 2018-02-14 14:47:43 -08:00
.gitignore Allow Operator Generated bootstrap token (#12520) 2022-06-03 07:37:24 -04:00
.go-version build: update to go1.18.3 2022-07-01 10:12:56 -05:00
.golangci.yml cleanup: purge github.com/pkg/errors 2022-04-01 19:24:02 -05:00
.semgrepignore build: disable semgrep on structs.go for now 2022-02-01 10:09:49 -06:00
CHANGELOG.md Post 1.3.1 release changes 2022-05-24 16:33:30 -04:00
CODEOWNERS add service acct to codeowners for backport merging 2022-05-06 10:06:20 -07:00
GNUmakefile build: update golangci-lint to v1.46.2 2022-05-31 23:32:01 +00:00
LICENSE Initial commit 2015-06-01 12:21:00 +02:00
README.md README: Align with Consul README (#9681) 2020-12-18 09:38:34 -08:00
Vagrantfile tools: update virtualbox networking configuration (#11561) 2021-11-24 10:45:58 -05:00
build_linux_arm.go gofmt all the files 2021-10-01 10:14:28 -04:00
go.mod build(deps): bump github.com/hashicorp/consul/sdk from 0.8.0 to 0.9.0 (#12007) 2022-07-12 12:58:34 -07:00
go.sum build(deps): bump github.com/hashicorp/consul/sdk from 0.8.0 to 0.9.0 (#12007) 2022-07-12 12:58:34 -07:00
main.go raw_exec: make raw exec driver work with cgroups v2 2022-04-04 16:11:38 -05:00
main_test.go Adding initial skeleton 2015-06-01 13:46:21 +02:00

README.md

Nomad Build Status Discuss

HashiCorp Nomad logo

Nomad is a simple and flexible workload orchestrator to deploy and manage containers (docker, podman), non-containerized applications (executable, Java), and virtual machines (qemu) across on-prem and clouds at scale.

Nomad is supported on Linux, Windows, and macOS. A commercial version of Nomad, Nomad Enterprise, is also available.

Nomad provides several key features:

  • Deploy Containers and Legacy Applications: Nomads flexibility as an orchestrator enables an organization to run containers, legacy, and batch applications together on the same infrastructure. Nomad brings core orchestration benefits to legacy applications without needing to containerize via pluggable task drivers.

  • Simple & Reliable: Nomad runs as a single binary and is entirely self contained - combining resource management and scheduling into a single system. Nomad does not require any external services for storage or coordination. Nomad automatically handles application, node, and driver failures. Nomad is distributed and resilient, using leader election and state replication to provide high availability in the event of failures.

  • Device Plugins & GPU Support: Nomad offers built-in support for GPU workloads such as machine learning (ML) and artificial intelligence (AI). Nomad uses device plugins to automatically detect and utilize resources from hardware devices such as GPU, FPGAs, and TPUs.

  • Federation for Multi-Region, Multi-Cloud: Nomad was designed to support infrastructure at a global scale. Nomad supports federation out-of-the-box and can deploy applications across multiple regions and clouds.

  • Proven Scalability: Nomad is optimistically concurrent, which increases throughput and reduces latency for workloads. Nomad has been proven to scale to clusters of 10K+ nodes in real-world production environments.

  • HashiCorp Ecosystem: Nomad integrates seamlessly with Terraform, Consul, Vault for provisioning, service discovery, and secrets management.

Quick Start

Testing

See Learn: Getting Started for instructions on setting up a local Nomad cluster for non-production use.

Optionally, find Terraform manifests for bringing up a development Nomad cluster on a public cloud in the terraform directory.

Production

See Learn: Nomad Reference Architecture for recommended practices and a reference architecture for production deployments.

Documentation

Full, comprehensive documentation is available on the Nomad website: https://www.nomadproject.io/docs

Guides are available on HashiCorp Learn.

Contributing

See the contributing directory for more developer documentation.