HashiCorp Nomad

Deploy HashiCorp Nomad, a simple and flexible scheduler and orchestrator for deploying and managing containerized and non-containerized applications across cloud platforms and on-premises servers at scale.

1. Deploy HashiCorp Nomad

 Estimated deployment time: 5–10 minutes

Follow the deployment instructions from the Get started section to configure the app, deploy it, and verify software installation.

For information on the app-specific configurations, see the Configuration options section.

Base distribution and plan

  • Supported distribution: Ubuntu 24.04 LTS
  • Recommended plans: Use a 4GB Dedicated CPU or Shared Compute Instance. Nomad clients, deployed separately, can use plans of any size.

Configuration options

Configure the required options to deploy your instance. For additional customization, add advanced options.

The table maps the Cloud Manager UI fields to their corresponding API/CLI keys (stackscript_data) required for automated deployments.

StackScript ID: 1037037

UI fieldAPI/CLI keyDescription
Required options
Limited sudo useruser_nameYour preferred username for the limited sudo user entered without any capital letters, spaces, or special characters.
When adding a limited sudo user, the user is created with a strong generated password for your new Linode instance, and the account is assigned to the sudo group, which provides elevated permissions when running commands with the sudo prefix.
Note: For easier and more secure access with the sudo user, add an account SSH key for the Cloud Manager user during deployment and select that user as an authorized_user. Their SSH pubkey will be assigned to both the root and limited user.
Email address (for the Let's Encrypt SSL certificate)soa_email_addressThe email address used for generating SSL certificates.
Advanced options
Disable root access over SSHdisable_rootApplies to a limited sudo user. To block the root user from logging in over SSH, select Yes. Defaults to No.
Note: When you disable the root user from logging in over SSH and don't provide a valid Account SSH Key assigned to the authorized_user, you can still switch to the root user. To do that, log in as root via the Lish console and run cat /home/$USERNAME/.credentials to view the generated password for the limited sudo user.
Linode API tokentoken_passwordApplies to a custom domain. The Linode API token if you want to use Linode's DNS Manager to manage DNS records for your custom domain. Follow Manage personal access tokens to get your token on your account with Read/Write access to Domains.
  • If you provide the token along with the subdomain and domain, the installation attempts to create DNS records via the Linode API.
  • If you don't provide the token, you need to manually configure your DNS records through your DNS provider and point them to the IP address of the new instance.
SubdomainsubdomainApplies to a custom domain. The subdomain you want to use, like blog for blog.example.com. Use it only if you specify a Domain.
DomaindomainApplies to a custom domain. The domain name you want to use, like example.com. Use it only if you specify a Linode API token.
NGINX Basic Auth username that gates the Nomad UInomad_htpasswd_userThe username used for NGINX basic authentication in front of the Nomad Web UI. Defaults to nomad.
Optional data exporter Add-onsadd_onsAn option to include add-ons for your deployment. Possible values are:
  • none (default)
  • newrelic
  • node_exporter
  • mysqld_exporter

Notes:

  • After the app deployment completes, the password for your limited sudo user is generated and stored in the ~/.deployment-secrets file in the home directory, along with the NGINX basic auth password for the Nomad UI. Log in to your instance as root through the Lish console or SSH, then run cat ~/.deployment-secrets.txt to view its contents.
  • You can automatically configure a custom domain (optional) during deployment. To do that:
    1. Configure your domain to use Linode's name servers via your registrar. See Configure your domain's authoritative name servers for details.
    2. Once you complete that, specify the Linode API token, subdomain, and domain for the app in Cloud Manager or via API/CLI/Terraform.

Use API, CLI, or Terraform

In addition to deploying the app to a new Linode instance via Cloud Manager, you can also use the Linode API, CLI, or Terraform. When running the operation, you need to provide the StackScript ID, supported Linux distribution, and app-specific fields along with the standard Linode deployment configurations.

Note: Generate a personal access token to authenticate your API, CLI, or Terraform requests.

curl --location 'https://api.linode.com/v4/linode/instances' \
    --header 'Content-Type: application/json' \
    --header 'Accept: application/json' \
    --header 'Authorization: Bearer abc123def456hij789klm' \
    --data-raw '{
        "region": "us-east",
        "type": "g6-dedicated-4",
        "image": "linode/ubuntu24.04",
        "label": "my-nomad-one-click-app",
        "root_pass": "@C0mpl3x#P@ssw0rd",
        "stackscript_id": 1037037,
        "stackscript_data": {
            "user_name": "jsmith",
            "soa_email_address": "jsmith@example.com"
        }
    }'
linode-cli linodes create \
    --region us-east \
    --type g6-dedicated-4 \
    --label my-nomad-one-click-app \
    --image linode/ubuntu24.04 \
    --root_pass @C0mpl3x#P@ssw0rd \
    --stackscript_id 1037037 \
    --stackscript_data '{"user_name":"jsmith", "soa_email_address":"jsmith@example.com"}'
resource "linode_instance" "my-linode" {
    region         = "us-east"
    type           = "g6-dedicated-4"
    label          = "my-nomad-one-click-app"
    image          = "linode/ubuntu24.04"
    root_pass      = "@C0mpl3x#P@ssw0rd"
    stackscript_id = 1037037
    stackscript_data = {
        "user_name"         = "jsmith"
        "soa_email_address" = "jsmith@example.com"
    }
}

2. Access the Nomad Web UI

  1. Open your web browser and navigate to http://[ip-address]:8080, replacing [ip-address] with your instance's IPv4 address.

    See the Manage IP addresses on a Linode guide for information on viewing IP addresses.

  2. The Nomad Web UI is displayed. From here, you can manage the cluster, jobs, integrations, and ACL tokens.

📘

HashiCorp recommends using mutual TLS (mTLS) with a private CA to secure cluster communications and the web UI. See the HashiCorp documentation for more details:

Additional resources

Additional configuration is required to use Nomad in a production environment. For more information, see their official documentation.

📘

Note that we can't vouch for the accuracy or timeliness of externally hosted resources.


Did this page help you?