Nomad
One command with nomad-pack (Nomploy)
Section titled “One command with nomad-pack (Nomploy)”The goliash pack runs the server with SQLite on a volume and watches the Nomad cluster it runs on, read-only,
without an agent. The matrix fills on its own:
nomad-pack registry add nomploy https://github.com/Nomploy/nomad-packsnomad-pack run goliash --registry=nomploy \ --var owner_email=you@example.com --var public_url=https://goliash.example.comThe first start logs a one-time sign-in link for owner_email in the task logs. With Nomad ACLs on, pass a token
with list-jobs and read-job as nomad_token. All variables are in the
pack README.
Server
Section titled “Server”deploy/nomad/goliash-server.nomad.hcl runs the server. SQLite lives in the host volume goliash-data, which
you declare in the client configuration. For PostgreSQL, put a URL in the job’s variable:
nomad var put nomad/jobs/goliash database_url=postgres://… # optionalnomad job run deploy/nomad/goliash-server.nomad.hclThe agent reads the cluster through the Nomad API with a token that has the list-jobs and read-job capabilities:
nomad acl policy apply goliash-read - <<<'namespace "*" { capabilities = ["list-jobs", "read-job"] }'nomad acl token create -name goliash-agent -policy goliash-read # copy the secret IDnomad var put nomad/jobs/goliash-agent token=glsh_enroll_… nomad_token=<secret ID>nomad job run -var server_url=https://goliash.example.com -var version=1.14.0 deploy/nomad/goliash-agent.nomad.hcltoken is the code from Connect (or goliash enroll create -env prod): the agent registers itself and adds the
region as a target, read through the Nomad agent on its node. The job passes the Nomad token to the agent as
GOLIASH_CREDENTIAL_NOMAD. With an agent token (glsh_agent_…) instead, create a nomad target with credentials
reference nomad and settings like {"nomad":{"address":"http://nomad.service.consul:4646"}}.
Run one agent per token: the job is a service job with one instance, not a system job.
What the Nomad collector reports
Section titled “What the Nomad collector reports”One workload per job, with a container per task (group/task) and its image, counted by running allocations.
During a deployment the old and new job versions show side by side. Optional settings: region and namespaces
(empty means every namespace the token can read).