Skip to content

Nomad

The goliash pack runs the server with SQLite on a volume and watches the Nomad cluster it runs on, read-only, without an agent. The matrix fills on its own:

Terminal window
nomad-pack registry add nomploy https://github.com/Nomploy/nomad-packs
nomad-pack run goliash --registry=nomploy \
--var owner_email=you@example.com --var public_url=https://goliash.example.com

The first start logs a one-time sign-in link for owner_email in the task logs. With Nomad ACLs on, pass a token with list-jobs and read-job as nomad_token. All variables are in the pack README.

deploy/nomad/goliash-server.nomad.hcl runs the server. SQLite lives in the host volume goliash-data, which you declare in the client configuration. For PostgreSQL, put a URL in the job’s variable:

Terminal window
nomad var put nomad/jobs/goliash database_url=postgres://… # optional
nomad job run deploy/nomad/goliash-server.nomad.hcl

The agent reads the cluster through the Nomad API with a token that has the list-jobs and read-job capabilities:

Terminal window
nomad acl policy apply goliash-read - <<<'namespace "*" { capabilities = ["list-jobs", "read-job"] }'
nomad acl token create -name goliash-agent -policy goliash-read # copy the secret ID
nomad var put nomad/jobs/goliash-agent token=glsh_enroll_… nomad_token=<secret ID>
nomad job run -var server_url=https://goliash.example.com -var version=1.14.0 deploy/nomad/goliash-agent.nomad.hcl

token is the code from Connect (or goliash enroll create -env prod): the agent registers itself and adds the region as a target, read through the Nomad agent on its node. The job passes the Nomad token to the agent as GOLIASH_CREDENTIAL_NOMAD. With an agent token (glsh_agent_…) instead, create a nomad target with credentials reference nomad and settings like {"nomad":{"address":"http://nomad.service.consul:4646"}}.

Run one agent per token: the job is a service job with one instance, not a system job.

One workload per job, with a container per task (group/task) and its image, counted by running allocations. During a deployment the old and new job versions show side by side. Optional settings: region and namespaces (empty means every namespace the token can read).