Your own cluster with the Nomad agent

Deploy from the ISOGrid console on a Docker Swarm or Kubernetes you run yourself, without giving ISOGrid any access to your machines or your secrets.

Some organizations cannot hand a cloud provider a key to their servers, and cannot let their secrets leave their network. The ISOGrid Nomad agent is for them. You run it on your own cluster; it connects to ISOGrid, never the other way round, and executes the deployments you order from the console.

What stays with you

  • Your machines. ISOGrid holds no SSH key and registers no node. The agent is the only thing that touches your cluster, and it runs on a manager you control.
  • Your secrets. ISOGrid knows the names of your secrets, never their values. You enter the values in the agent's own console on your network, and the agent keeps them in your HashiCorp Vault or OpenBao.
  • Your logs. Build and container logs stay on your network and are read in the agent's console only.
  • Your web tier. You keep your own NGINX or HAProxy. The platform writes no web server configuration and allocates no port on an agent cluster.

The agent's code is public, so your team can read exactly what it does before running it: github.com/ISOGrid-by-SkyVault/isogrid-nomad-agent.

How it connects

The agent opens one outbound connection to ISOGrid over HTTPS, the same address and certificate as this console, and proves who it is with the certificate issued for your cluster. ISOGrid accepts it only from the addresses you declared. Every order ISOGrid sends is signed with a key that belongs to your organization; the agent verifies the signature before it looks at the order, and refuses anything else.

Setting it up

  1. Open Integrations and choose ISOGrid Nomad agent.
  2. Enter the public addresses your agents connect from, one per line, and enable the integration.
  3. Add a cluster: a name and whether it runs Docker Swarm or Kubernetes. The price per cluster is shown before you confirm.
  4. Download the cluster's bundle: five files, including the certificate and the signing key the agent needs.
  5. On a Swarm manager, unzip the bundle in a directory and run the installer:
curl -fsSL https://raw.githubusercontent.com/ISOGrid-by-SkyVault/isogrid-nomad-agent/main/install.sh -o install.sh
sudo bash install.sh

The installer asks which networks the agent joins, where its console listens, where the bundle is, and how to reach your Vault. Once the agent connects, the cluster shows as connected on the Integrations page.

If the certificate is lost

Use New certificate on the cluster: the old bundle stops working and the new one must be installed. Removing a cluster from ISOGrid changes nothing on your machines.