Go to file
Seth Hoenig c68ed3b4c8
client: protect user lookups with global lock (#14742)
* client: protect user lookups with global lock

This PR updates Nomad client to always do user lookups while holding
a global process lock. This is to prevent concurrency unsafe implementations
of NSS, but still enabling NSS lookups of users (i.e. cannot not use osusergo).

* cl: add cl
2022-09-29 09:30:13 -05:00
.changelog client: protect user lookups with global lock (#14742) 2022-09-29 09:30:13 -05:00
.circleci build: update go version to go1.19.1 (#14653) 2022-09-22 09:40:01 -05:00
.github build: update go version to go1.19.1 (#14653) 2022-09-22 09:40:01 -05:00
.release Prepare for next release 2022-09-27 17:33:32 -04:00
.semgrep Data race fixes in tests and a new semgrep rule (#14594) 2022-09-15 10:35:08 -07:00
.tours Make number of scheduler workers reloadable (#11593) 2022-01-06 11:56:13 -05:00
acl rename SecureVariables to Variables throughout 2022-08-26 16:06:24 -04:00
api build(deps): bump github.com/docker/go-units from 0.4.0 to 0.5.0 in /api (#14430) 2022-09-26 09:30:17 -05:00
ci ci: fixup task runner chroot test 2022-04-19 10:37:46 -05:00
client client: protect user lookups with global lock (#14742) 2022-09-29 09:30:13 -05:00
command client: protect user lookups with global lock (#14742) 2022-09-29 09:30:13 -05:00
contributing build: update go version to go1.19.1 (#14653) 2022-09-22 09:40:01 -05:00
demo demo/docs: update demo of Kadalu CSI Plugin (#13610) 2022-07-06 10:24:34 -04:00
dev docs: swap master for main in Nomad repo 2021-03-08 14:26:31 -05:00
drivers client: protect user lookups with global lock (#14742) 2022-09-29 09:30:13 -05:00
e2e e2e: convert chroot env unit tests into e2e tests (#14710) 2022-09-26 15:40:29 -05:00
helper client: protect user lookups with global lock (#14742) 2022-09-29 09:30:13 -05:00
integrations spelling: registrations 2018-03-11 18:40:53 +00:00
internal/testing/apitests cleanup: replace TypeToPtr helper methods with pointer.Of (#14151) 2022-08-17 18:26:34 +02:00
jobspec jobspec: allow artifact headers in HCLv1 (#14637) 2022-09-27 12:18:49 -04:00
jobspec2 hcl2: add strlen function and update docs. (#14463) 2022-09-06 18:42:40 +02:00
lib remove unused circbufwriter code (#14593) 2022-09-15 10:33:33 -07:00
nomad Prepare for next release 2022-09-27 17:33:32 -04:00
plugins cleanup more helper updates (#14638) 2022-09-21 14:53:25 -05:00
scheduler core: numeric operands comparisons in constraints (#14722) 2022-09-27 11:07:07 -05:00
scripts build: update go version to go1.19.1 (#14653) 2022-09-22 09:40:01 -05:00
terraform terraform: update installed versions of HashiCorp tools. (#13635) 2022-07-07 16:12:19 +02:00
testutil fingerprint: don't clear Consul/Vault attributes on failure (#14673) 2022-09-23 14:45:12 -04:00
tools build: make ec2info command usable from GNUMakefile 2022-09-09 08:48:12 -05:00
ui Visual diff tests: error states (#14707) 2022-09-27 15:46:33 -04:00
version Prepare for next release 2022-09-27 17:33:32 -04:00
website Merge pull request #14664 from hashicorp/docs-multiregion-dispatch 2022-09-28 15:40:11 -04:00
.git-blame-ignore-revs ignore b0a20b4dc965a38b0c843f47c16685ccad7439da (#13648) 2022-07-07 15:16:18 -07:00
.gitattributes Remove invalid gitattributes 2018-02-14 14:47:43 -08:00
.gitignore Allow Operator Generated bootstrap token (#12520) 2022-06-03 07:37:24 -04:00
.go-version build: update go version to go1.19.1 (#14653) 2022-09-22 09:40:01 -05:00
.golangci.yml cleanup: purge github.com/pkg/errors 2022-04-01 19:24:02 -05:00
.semgrepignore build: disable semgrep on structs.go for now 2022-02-01 10:09:49 -06:00
CHANGELOG.md Apply changes from code review 2022-09-27 17:33:32 -04:00
CODEOWNERS add service acct to codeowners for backport merging 2022-05-06 10:06:20 -07:00
GNUmakefile client: protect user lookups with global lock (#14742) 2022-09-29 09:30:13 -05:00
LICENSE
README.md readme: remove Gitter lobby link. (#14195) 2022-08-22 10:33:20 +02:00
Vagrantfile tools: update virtualbox networking configuration (#11561) 2021-11-24 10:45:58 -05:00
build_linux_arm.go gofmt all the files 2021-10-01 10:14:28 -04:00
go.mod build(deps): bump github.com/hashicorp/go-uuid from 1.0.2 to 1.0.3 (#14688) 2022-09-26 09:55:40 -05:00
go.sum build(deps): bump github.com/hashicorp/go-uuid from 1.0.2 to 1.0.3 (#14688) 2022-09-26 09:55:40 -05:00
main.go raw_exec: make raw exec driver work with cgroups v2 2022-04-04 16:11:38 -05:00
main_test.go

README.md

Nomad License: MPL 2.0 Discuss

HashiCorp Nomad logo

Nomad is a simple and flexible workload orchestrator to deploy and manage containers (docker, podman), non-containerized applications (executable, Java), and virtual machines (qemu) across on-prem and clouds at scale.

Nomad is supported on Linux, Windows, and macOS. A commercial version of Nomad, Nomad Enterprise, is also available.

Nomad provides several key features:

  • Deploy Containers and Legacy Applications: Nomads flexibility as an orchestrator enables an organization to run containers, legacy, and batch applications together on the same infrastructure. Nomad brings core orchestration benefits to legacy applications without needing to containerize via pluggable task drivers.

  • Simple & Reliable: Nomad runs as a single binary and is entirely self contained - combining resource management and scheduling into a single system. Nomad does not require any external services for storage or coordination. Nomad automatically handles application, node, and driver failures. Nomad is distributed and resilient, using leader election and state replication to provide high availability in the event of failures.

  • Device Plugins & GPU Support: Nomad offers built-in support for GPU workloads such as machine learning (ML) and artificial intelligence (AI). Nomad uses device plugins to automatically detect and utilize resources from hardware devices such as GPU, FPGAs, and TPUs.

  • Federation for Multi-Region, Multi-Cloud: Nomad was designed to support infrastructure at a global scale. Nomad supports federation out-of-the-box and can deploy applications across multiple regions and clouds.

  • Proven Scalability: Nomad is optimistically concurrent, which increases throughput and reduces latency for workloads. Nomad has been proven to scale to clusters of 10K+ nodes in real-world production environments.

  • HashiCorp Ecosystem: Nomad integrates seamlessly with Terraform, Consul, Vault for provisioning, service discovery, and secrets management.

Quick Start

Testing

See Learn: Getting Started for instructions on setting up a local Nomad cluster for non-production use.

Optionally, find Terraform manifests for bringing up a development Nomad cluster on a public cloud in the terraform directory.

Production

See Learn: Nomad Reference Architecture for recommended practices and a reference architecture for production deployments.

Documentation

Full, comprehensive documentation is available on the Nomad website: https://www.nomadproject.io/docs

Guides are available on HashiCorp Learn.

Contributing

See the contributing directory for more developer documentation.