documentation
Nomad
Our great sponsors
documentation | Nomad | |
---|---|---|
5 | 94 | |
454 | 14,422 | |
- | 0.8% | |
6.1 | 9.9 | |
almost 3 years ago | about 10 hours ago | |
Shell | Go | |
Apache License 2.0 | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
documentation
-
Speed boost achievement unlocked on Docker Desktop 4.6 for Mac
Both Kata Containers and UTM support virtio-fs, so this is not strictly true. The former can be used as a stand-in replacement for the runtime used by docker desktop[1]. With the latter, one could use a UTM-backed guest as a docker runtime in macOS[2] or run docker directly on the guest[3].
[1] https://github.com/kata-containers/documentation/blob/master...
[2] https://www.codeluge.com/post/setting-up-docker-on-macos-m1-...
[3] https://www.lifeintech.com/2021/11/03/docker-performance-on-...
-
Kubernetes Security Checklist 2021
For services with increased security requirements, it is recommended to use a low-level run-time with a high degree of isolation (gVisior, Kata-runtime)
-
Kata Containers on GKE?
On the official Kata repo, I found a tutorial only for manually deployed Kubernetes on GCE.
-
Monitoring Elixir Apps on Fly.io with Prometheus and PromEx
This is new and may not be used much, but it is possible to use part of Kata with part of Firecracker. https://github.com/kata-containers/documentation/wiki/Initia...
-
Docker Without Docker
If it's using firecracker, it's probably using KVM virtualization while ensuring that the memory the VM consumes is not pinned... that is, that the VM can be swapped out of memory. For reference, firecracker was created by AWS to run and secure AWS Lambda. The hypervisor is written in rust and uses seccomp to eliminate unnecessary system calls. They open sourced it a few years back.
What you gain is a stronger security boundary. Just FYI, since 2019, you can also do this in Kubernetes using Kata containers which will happily shim firecracker. The setup is not simple though.
https://github.com/kata-containers/documentation/wiki/Initia...
Overall, fly.io building infrastructure on this pattern is fantastic and making it accessible is fantastic. Looking forward to seeing how this continues to evolve and am happy to see more infra build on top of firecracker. Very exciting!
Nomad
-
IBM Planning to Acquire HashiCorp
I don't have any further insight, but looking at <https://github.com/hashicorp/nomad/forks?include=active&page...> coughed up https://github.com/atlassian/nomad/branches although confusingly it says "updated last week" but browsing any one of the branches seems to be stupid old so I got nothing
Finding conceptual forks, e.g. $(git push --mirror ...) would be trickier but I bet sourcegraph could do it
Ultimately, the question boils down to: what risk are you driving down: hitching your wagon to a dead stack, not getting security updates, not getting PRs merged, $other?
-
Running Docker based web applications in Hashicorp Nomad with Traefik Load balancing
In previous post, we discussed creating a basic Nomad cluster in the Vultr cloud. Here, we will use the cluster created to deploy a load-balanced sample web app using the service discovery capability of Nomad and its native integration with the Traefik load balancer. The source code is available here for the reference.
-
Building HashiCorp Nomad Cluster in Vultr Cloud using Terraform
Nomad is really awesome!
-
K0s: Kubernetes distro as a single binary with zero host OS dependencies
I only heard of this today, but it looks really interesting. It seems to finally get Kubernetes a bit closer to something like https://www.nomadproject.io/ in terms of complexity to install and operate.
-
Embracing Simplicity: The Advantages of Nomad over Kubernetes
In the rapidly evolving landscape of container orchestration and management, two prominent players have emerged: Kubernetes and HashiCorp's Nomad. While Kubernetes has gained widespread adoption and popularity, Nomad provides a compelling alternative that stands out for its simplicity and efficiency. In this blog post, we'll explore the advantages of using Nomad over Kubernetes and why it might be the right choice for certain use cases.
-
HashiCorp Vault Forked into OpenBao
I can't discern how many are just those "dependabot" bumps but the 1400 forks show some are active https://github.com/hashicorp/nomad/forks?include=active&page... including CircleCI who I would think have a stake in a libre Nomad https://github.com/circleci/nomad/tree/circleci/release-1.5....
Now maybe their goals don't align with the community, and/or they don't want to be in the maintainer business for such a project, but better than nothing
-
Remote execution of code
Could this be a solution? nomad
- Google Kubernetes Engine incident spanning 9 days
-
Homebrew deprecate and add caveat for HashiCorp
It worth noting that Nomad UI(a official web admin panel) has log tailing utility built-in so maybe partial work has already been done. The developers may have other concerns.
The related issue is https://github.com/hashicorp/nomad/issues/10220
-
HashiCorp Adopts Business Source License
While I do understand the reasoning in their FAQ on the subject (https://www.hashicorp.com/license-faq). I however failed to noticed those intentions in their license text (https://github.com/hashicorp/nomad/commit/b3e30b1dfa185d9437...).
Specifically the part in FAQ which says "internal production use is fine", but then license says that "non-production use only" and then "You may make production use of the Licensed Work, provided such use does not include offering the Licensed Work to third parties on a hosted or embedded basis which is competitive with HashiCorp's products.".
IANAL, but even to me this statement is full loopholes. WHO do we consider 3rd party? WHAT do we consider "hosted or embedded basis"? WHEN do we consider it "competitive with Hashicorps products"?
What are some alternatives?
grype - A vulnerability scanner for container images and filesystems
k3s - Lightweight Kubernetes
kubevirt - Kubernetes Virtualization API and runtime in order to define and manage virtual machines.
Rundeck - Enable Self-Service Operations: Give specific users access to your existing tools, services, and scripts
simplenetes - The sns tool is used to manage the full life cycle of your Simplenetes clusters. It integrates with the Simplenetes Podcompiler project podc to compile pods.
Dkron - Dkron - Distributed, fault tolerant job scheduling system https://dkron.io
oci-seccomp-bpf-hook - OCI hook to trace syscalls and generate a seccomp profile
Docker Compose - Define and run multi-container applications with Docker
krane - Kubernetes RBAC static analysis & visualisation tool
dapr - Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge.
cvehound - Check linux sources dump for known CVEs.
podman - Podman: A tool for managing OCI containers and pods.