nomad

created pr with 3.1 on 2025-02-01 · by 8c45d02c
cmds
checkout latest patchset:
ssh pr.in0rdr.ch print 3 | git am -3
checkout any patchset in a patch request:
ssh pr.in0rdr.ch print 3.[rev] | git am -3
add changes to patch request:
git format-patch main --stdout | ssh pr.in0rdr.ch pr add 3

Patchset 3.1 on 2025-02-01 · commit 7a10d35

feat: add silverbullet
Andreas Gruhler 2025-02-01
Semantic diff summary
0 added, 0 modified, 0 signature changed, 0 removed across 0 analyzed files (3 files skipped: unsupported file type)
+31 -0 hcl/default/silverbullet/data-volume.hcl #
......@@ -0,0 +1,31 @@
1+# Register external nfs volume with Nomad CSI
2+# https://www.nomadproject.io/docs/commands/volume/register
3+type = "csi"
4+# Unique ID of the volume, volume.source field in a job
5+id = "silverbullet"
6+# Display name of the volume.
7+name = "silverbullet"
8+# ID of the physical volume from the storage provider
9+external_id = "csi-silverbullet"
10+plugin_id = "nfs"
11+
12+# You must provide at least one capability block
13+# You must provide a block for each capability
14+# youintend to use in a job's volume block
15+# https://www.nomadproject.io/docs/commands/volume/register
16+capability {
17+ access_mode = "multi-node-multi-writer"
18+ attachment_mode = "file-system"
19+}
20+
21+# https://github.com/kubernetes-csi/csi-driver-nfs/blob/master/docs/driver-parameters.md
22+context {
23+ server = "turris"
24+ share = "csi-silverbullet"
25+}
26+
27+mount_options {
28+ # mount.nfs: Either use '-o nolock' to keep locks local, or start statd.
29+ mount_flags = ["nolock"]
30+}
31+
+89 -0 hcl/default/silverbullet/silverbullet.nomad #
......@@ -0,0 +1,89 @@
1+# https://silverbullet.md/Install/Docker
2+job "silverbullet" {
3+ datacenters = ["dc1"]
4+
5+ vault {}
6+
7+ group "server" {
8+ count = 1
9+
10+ volume "silverbullet" {
11+ type = "csi"
12+ source = "silverbullet"
13+ access_mode = "multi-node-multi-writer"
14+ attachment_mode = "file-system"
15+ }
16+ volume "tls" {
17+ type = "csi"
18+ source = "certbot"
19+ access_mode = "multi-node-multi-writer"
20+ attachment_mode = "file-system"
21+ }
22+
23+ network {
24+ port "http" {
25+ to = 3000
26+ }
27+ port "https" {
28+ static = 44407
29+ }
30+ }
31+
32+ task "silverbullet" {
33+ driver = "podman"
34+
35+ config {
36+ image = "docker.io/zefhemel/silverbullet:latest"
37+ ports = ["http"]
38+ }
39+
40+ template {
41+ destination = "${NOMAD_SECRETS_DIR}/silverbullet.env"
42+ env = true
43+ data = <<EOT
44+SB_USER = "{{with secret "kv/silverbullet"}}{{index .Data.data.sb_user}}{{end}}"
45+EOT
46+ }
47+
48+ volume_mount {
49+ volume = "silverbullet"
50+ destination = "/space"
51+ }
52+
53+ resources {
54+ memory = 256
55+ memory_max = 512
56+ cpu = 250
57+ }
58+ }
59+
60+ task "nginx" {
61+ driver = "podman"
62+
63+ config {
64+ image = "docker.io/library/nginx:stable-alpine"
65+ ports = ["https"]
66+ volumes = [
67+ # mount the templated config from the task directory to the container
68+ "local/silverbullet.conf:/etc/nginx/conf.d/silverbullet.conf",
69+ ]
70+ }
71+
72+ volume_mount {
73+ volume = "tls"
74+ destination = "/etc/letsencrypt"
75+ }
76+
77+ template {
78+ destination = "${NOMAD_TASK_DIR}/silverbullet.conf"
79+ data = file("./templates/nginx.conf.tmpl")
80+ }
81+
82+ resources {
83+ memory = 50
84+ memory_max = 128
85+ cpu = 200
86+ }
87+ }
88+ }
89+}
+10 -0 hcl/default/silverbullet/templates/nginx.conf.tmpl #
......@@ -0,0 +1,10 @@
1+server {
2+ listen {{ env "NOMAD_PORT_https" }} ssl;
3+
4+ ssl_certificate /etc/letsencrypt/live/notes.in0rdr.ch/fullchain.pem;
5+ ssl_certificate_key /etc/letsencrypt/live/notes.in0rdr.ch/privkey.pem;
6+
7+ location / {
8+ proxy_pass http://{{ env "NOMAD_ADDR_http" }};
9+ }
10+}
Back to top