Go to file
James Rasell d7b311ce55
acl: correctly resolve ACL roles within client cache. (#14922)
The client ACL cache was not accounting for tokens which included
ACL role links. This change modifies the behaviour to resolve role
links to policies. It will also now store ACL roles within the
cache for quick lookup. The cache TTL is configurable in the same
manner as policies or tokens.

Another small fix is included that takes into account the ACL
token expiry time. This was not included, which meant tokens with
expiry could be used past the expiry time, until they were GC'd.
2022-10-20 09:37:32 +02:00
.changelog acl: correctly resolve ACL roles within client cache. (#14922) 2022-10-20 09:37:32 +02:00
.circleci build: update go version to go1.19.1 (#14653) 2022-09-22 09:40:01 -05:00
.github lock closed issues and PRs after 120 days (#14824) 2022-10-06 16:18:00 -04:00
.release Prepare for next release 2022-10-06 09:16:01 -07:00
.semgrep semgrep: add MeasureSinceWithLabels to FSM time rule (#14812) 2022-10-06 10:59:53 -04:00
.tours
acl rename SecureVariables to Variables throughout 2022-08-26 16:06:24 -04:00
api api: add convenience string func to Topic type. (#14843) 2022-10-19 14:12:23 +02:00
ci
client acl: correctly resolve ACL roles within client cache. (#14922) 2022-10-20 09:37:32 +02:00
command acl: correctly resolve ACL roles within client cache. (#14922) 2022-10-20 09:37:32 +02:00
contributing internals documentation with diagrams (#14750) 2022-10-03 14:06:41 -04:00
demo demo/docs: update demo of Kadalu CSI Plugin (#13610) 2022-07-06 10:24:34 -04:00
dev
drivers client: protect user lookups with global lock (#14742) 2022-09-29 09:30:13 -05:00
e2e e2e: convert flaky exec download in chroot unit test into e2e test (#14949) 2022-10-19 08:22:32 -05:00
helper helpers: lockfree lookup of nobody user on unix systems (#14866) 2022-10-11 08:38:05 -05:00
integrations
internal/testing/apitests cleanup: replace TypeToPtr helper methods with pointer.Of (#14151) 2022-08-17 18:26:34 +02:00
jobspec jobspec: allow artifact headers in HCLv1 (#14637) 2022-09-27 12:18:49 -04:00
jobspec2 hcl2: add strlen function and update docs. (#14463) 2022-09-06 18:42:40 +02:00
lib cleanup: rename Equals to Equal for consistency (#14759) 2022-10-10 09:28:46 -05:00
nomad acl: gate ACL role write and delete RPC usage on v1.4.0 or greater. (#14908) 2022-10-18 16:46:11 +02:00
plugins cleanup more helper updates (#14638) 2022-09-21 14:53:25 -05:00
scheduler make version checks specific to region (1.4.x) (#14912) 2022-10-17 16:23:51 -04:00
scripts build: update go version to go1.19.1 (#14653) 2022-09-22 09:40:01 -05:00
terraform terraform: update installed versions of HashiCorp tools. (#13635) 2022-07-07 16:12:19 +02:00
testutil Fixing flaky TestOverlap test (#14780) 2022-10-03 14:35:02 -07:00
tools deps: remove gophers.dev dependency (#14789) 2022-10-04 09:49:50 -04:00
ui Adds searching and filtering for nodes on topology view (#14913) 2022-10-19 15:00:35 -04:00
version Prepare for next release 2022-10-06 09:16:01 -07:00
website acl: correctly resolve ACL roles within client cache. (#14922) 2022-10-20 09:37:32 +02:00
.git-blame-ignore-revs ignore b0a20b4dc965a38b0c843f47c16685ccad7439da (#13648) 2022-07-07 15:16:18 -07:00
.gitattributes
.gitignore Allow Operator Generated bootstrap token (#12520) 2022-06-03 07:37:24 -04:00
.go-version build: update go version to go1.19.1 (#14653) 2022-09-22 09:40:01 -05:00
.golangci.yml
.semgrepignore
CHANGELOG.md Merge release 1.4.0 files 2022-10-06 09:24:54 -07:00
CODEOWNERS
GNUmakefile build: add ability to specify release targets (#14957) 2022-10-19 10:27:47 -07:00
LICENSE [COMPLIANCE] Update MPL 2.0 LICENSE (#14884) 2022-10-13 08:43:12 -04:00
README.md readme: remove Gitter lobby link. (#14195) 2022-08-22 10:33:20 +02:00
Vagrantfile
build_linux_arm.go
go.mod deps: update consul-template to `61e288a` (#14955) 2022-10-19 16:27:14 +02:00
go.sum deps: update consul-template to `61e288a` (#14955) 2022-10-19 16:27:14 +02:00
main.go docker_logger: reorder imports to save memory (#14875) 2022-10-11 13:23:03 -04:00
main_test.go

README.md

Nomad License: MPL 2.0 Discuss

HashiCorp Nomad logo

Nomad is a simple and flexible workload orchestrator to deploy and manage containers (docker, podman), non-containerized applications (executable, Java), and virtual machines (qemu) across on-prem and clouds at scale.

Nomad is supported on Linux, Windows, and macOS. A commercial version of Nomad, Nomad Enterprise, is also available.

Nomad provides several key features:

  • Deploy Containers and Legacy Applications: Nomads flexibility as an orchestrator enables an organization to run containers, legacy, and batch applications together on the same infrastructure. Nomad brings core orchestration benefits to legacy applications without needing to containerize via pluggable task drivers.

  • Simple & Reliable: Nomad runs as a single binary and is entirely self contained - combining resource management and scheduling into a single system. Nomad does not require any external services for storage or coordination. Nomad automatically handles application, node, and driver failures. Nomad is distributed and resilient, using leader election and state replication to provide high availability in the event of failures.

  • Device Plugins & GPU Support: Nomad offers built-in support for GPU workloads such as machine learning (ML) and artificial intelligence (AI). Nomad uses device plugins to automatically detect and utilize resources from hardware devices such as GPU, FPGAs, and TPUs.

  • Federation for Multi-Region, Multi-Cloud: Nomad was designed to support infrastructure at a global scale. Nomad supports federation out-of-the-box and can deploy applications across multiple regions and clouds.

  • Proven Scalability: Nomad is optimistically concurrent, which increases throughput and reduces latency for workloads. Nomad has been proven to scale to clusters of 10K+ nodes in real-world production environments.

  • HashiCorp Ecosystem: Nomad integrates seamlessly with Terraform, Consul, Vault for provisioning, service discovery, and secrets management.

Quick Start

Testing

See Learn: Getting Started for instructions on setting up a local Nomad cluster for non-production use.

Optionally, find Terraform manifests for bringing up a development Nomad cluster on a public cloud in the terraform directory.

Production

See Learn: Nomad Reference Architecture for recommended practices and a reference architecture for production deployments.

Documentation

Full, comprehensive documentation is available on the Nomad website: https://www.nomadproject.io/docs

Guides are available on HashiCorp Learn.

Contributing

See the contributing directory for more developer documentation.