Skip to content

feat(cluster): add worker nodes from the UI (WireGuard mesh) - #16

Merged
pipozzz merged 1 commit into
mainfrom
feat/multinode-cluster-ui
Sep 2, 2026
Merged

pipozzz merged 1 commit into
mainfrom
feat/multinode-cluster-ui

Conversation

@pipozzz

@pipozzz pipozzz commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Productizes multi-node Nomad clustering (verified manually on 2 servers: WG mesh + 2 Nomad nodes + count=2 job spread across both).

  • nomad-cluster.ts getClusterWorkerJoinCommand() — worker install + WireGuard join + Consul/Nomad client, prints its WG pubkey.
  • nomad.joinCluster tRPC subscription — reads cluster.json, allocates overlay IP, runs the join over SSH (streamed), registers the peer on the hub, persists it.
  • install.sh — control plane becomes a WireGuard hub (gossip encryption); Consul/Nomad bind the overlay (HTTP stays on 127.0.0.1 for the app); writes cluster.json; app runs with NET_ADMIN + /etc/wireguard.
  • Dockerfile — wireguard-tools + iptables.
  • UI — 'Join cluster' button + streamed logs.

🤖 Generated with Claude Code

…eGuard mesh)

Turns the manually-proven multi-node setup into a product feature.

- nomad-cluster.ts: getClusterWorkerJoinCommand() generates a script (run over
  SSH) that installs Docker+Consul+Nomad+CNI+WireGuard on a worker, joins the
  WireGuard overlay (peers with the hub), and starts Consul/Nomad as clients
  that retry-join the hub. Prints WORKER_WG_PUBKEY for the hub to register.
- nomad.joinCluster tRPC subscription: reads /etc/nomploy/cluster.json, allocates
  the next overlay IP, runs the join script (streaming), registers the worker's
  WireGuard peer on the hub (wg set + wg-quick save), persists the peer, and sets
  the server's nomadAddress.
- install.sh: control plane is now a WireGuard hub (wg0 10.10.0.1, gossip
  encryption); Consul/Nomad bind to the overlay (HTTP still on 127.0.0.1 for the
  app); writes /etc/nomploy/cluster.json. App runs with NET_ADMIN + /etc/wireguard
  mounted so it can manage hub peers.
- Dockerfile: add wireguard-tools + iptables (app manages the hub's wg0).
- UI: 'Join cluster' button + streamed logs in the server's Nomad settings.

Manually verified end-to-end on two servers: WireGuard mesh + 2-node Nomad
cluster + a count=2 job spread across both nodes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@pipozzz
pipozzz merged commit 4393b65 into main Sep 2, 2026
@pipozzz
pipozzz deleted the feat/multinode-cluster-ui branch September 2, 2026 09:58
@github-actions

github-actions Bot commented Sep 2, 2026

Copy link
Copy Markdown

Thank you for your contribution! Please sign our Contributor License Agreement by posting the following comment:


I have read the CLA Document and I hereby sign the CLA


Peter Gonda seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You can retrigger this bot by commenting recheck in this Pull Request. Posted by the CLA Assistant Lite bot.

@github-actions github-actions Bot locked and limited conversation to collaborators Sep 2, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant