Deploy from the ISOGrid console on a Docker Swarm or Kubernetes you run yourself, without giving ISOGrid any access to your machines or your secrets.
Some organizations cannot hand a cloud provider a key to their servers, and
cannot let their secrets leave their network. The ISOGrid Nomad agent is for
them. You run it on your own cluster; it connects to ISOGrid, never the other
way round, and executes the deployments you order from the console.
What stays with you
Your machines. ISOGrid holds no SSH key and registers no node. The agent
is the only thing that touches your cluster, and it runs on a manager you
control.
Your secrets. ISOGrid knows the names of your secrets, never their
values. You enter the values in the agent's own console on your network, and
the agent keeps them in your HashiCorp Vault or OpenBao.
Your logs. Build and container logs stay on your network and are read in
the agent's console only.
Your web tier. You keep your own NGINX or HAProxy. The platform writes
no web server configuration and allocates no port on an agent cluster.
The agent opens one outbound connection to ISOGrid over HTTPS, the same
address and certificate as this console, and proves who it is with the
certificate issued for your cluster. ISOGrid accepts it only from the
addresses you declared. Every order ISOGrid sends is signed with a key that
belongs to your organization; the agent verifies the signature before it looks
at the order, and refuses anything else.
Setting it up
Open Integrations and choose ISOGrid Nomad agent.
Enter the public addresses your agents connect from, one per line, and
enable the integration.
Add a cluster: a name and whether it runs Docker Swarm or Kubernetes. The
price per cluster is shown before you confirm.
Download the cluster's bundle: five files, including the certificate and
the signing key the agent needs.
On a Swarm manager, unzip the bundle in a directory and run the installer:
The installer asks which networks the agent joins, where its console listens,
where the bundle is, and how to reach your Vault. Once the agent connects, the
cluster shows as connected on the Integrations page.
If the certificate is lost
Use New certificate on the cluster: the old bundle stops working and the
new one must be installed. Removing a cluster from ISOGrid changes nothing on
your machines.