Pama

HashiCorp Nomad 简介

在当今云原生时代,容器编排平台已经成为了现代基础设施不可或缺的组成部分。除了广为人知的 Kubernetes 之外,HashiCorp 公司开发的 Nomad 也是一个非常优秀的选择。本文将简要介绍 Nomad 及其主要特点。

什么是 Nomad?

Nomad 是 HashiCorp 公司推出的一个轻量级的分布式、高可用的容器编排与工作负载管理平台。它支持容器化和非容器化应用程序的部署与管理。作为一个单一的二进制文件,Nomad 的部署和维护都异常简单。

Nomad 的核心特性

1. 简单性

  • 单一二进制文件部署
  • 最小化的基础设施要求
  • 直观的命令行界面
  • 清晰的作业规范格式

2. 灵活性

  • 支持多种工作负载类型(Docker、虚拟机、Java 等)
  • 跨数据中心和区域的调度能力
  • 可以与现有工具集成
  • 支持多种驱动程序(Docker、QEMU、Java 等)

3. 可扩展性

  • 可处理大规模集群(支持上万个节点)
  • 高效的任务调度算法
  • 支持增量作业更新
  • 内置的故障转移机制

与 Kubernetes 的比较

相比 Kubernetes,Nomad 具有以下独特优势:

  1. 更轻量级:Nomad 是一个单一的二进制文件,安装部署更简单,学习曲线更平缓。
  2. 更灵活的工作负载支持:除了容器化应用,Nomad 还能管理传统应用、批处理作业等多种工作负载。
  3. 更简单的架构:Nomad 的架构更加简单,不需要太多的外部依赖,维护成本更低。

实际应用场景

Nomad 适用于以下场景:

  • 中小型组织的容器编排需求
  • 混合工作负载环境(既有容器又有传统应用)
  • 边缘计算场景
  • CI/CD 流水线的任务调度
  • 大规模批处理作业管理

命令行工具详解

Usage: nomad [-version] [-help] [-autocomplete-(un)install] <command> [args]
 
Common commands:
    run         Run a new job or update an existing job
    stop        Stop a running job
    status      Display the status output for a resource
    alloc       Interact with allocations
    job         Interact with jobs
    node        Interact with nodes
    agent       Runs a Nomad agent
 
Other commands:
    acl                 Interact with ACL policies and tokens
    agent-info          Display status information about the local agent
    config              Interact with configurations
    deployment          Interact with deployments
    eval                Interact with evaluations
    exec                Execute commands in task
    fmt                 Rewrites Nomad config and job files to canonical format
    license             Interact with Nomad Enterprise License
    login               Login to Nomad using an auth method
    monitor             Stream logs from a Nomad agent
    namespace           Interact with namespaces
    operator            Provides cluster-level tools for Nomad operators
    plugin              Inspect plugins
    quota               Interact with quotas
    recommendation      Interact with the Nomad recommendation endpoint
    scaling             Interact with the Nomad scaling endpoint
    sentinel            Interact with Sentinel policies
    server              Interact with servers
    service             Interact with registered services
    system              Interact with the system API
    tls                 Generate Self Signed TLS Certificates for Nomad
    ui                  Open the Nomad Web UI
    var                 Interact with variables
    version             Prints the Nomad version
    volume              Interact with volumes

常用命令

run:运行作业

用于部署新作业或更新现有作业。

# 从文件部署作业
nomad run nginx.job.hcl
 
# 运行作业并进行计划预览
nomad run -plan nginx.job.hcl
 
# 使用变量运行作业
nomad run -var="version=1.2.3" nginx.job.hcl

stop:停止作业

停止正在运行的作业。

# 停止指定作业
nomad stop nginx
 
# 停止并清除作业
nomad stop -purge nginx
 
# 停止并等待完成
nomad stop -detach=false nginx

status:查看状态

显示各种资源的状态信息。

# 查看所有作业状态
nomad status
 
# 查看特定作业详情
nomad status nginx

alloc:分配管理

管理和查看任务分配情况。

# 查看分配状态
nomad alloc status <alloc-id>
 
# 查看特定分配的日志
nomad alloc logs <alloc-id>
 
# 查看分配的详细信息
nomad alloc status -verbose <alloc-id>

job:作业管理

完整的作业生命周期管理。

# 查看作业历史
nomad job history nginx
 
# 校验作业文件
nomad job validate nginx.job.hcl
 
# 查看作业版本
nomad job history -p nginx

node:节点管理

集群节点的管理和监控。

# 列出所有节点
nomad node status
 
# 开启节点维护模式
nomad node drain -enable <node-id>
 
# 查看节点详细信息
nomad node status -verbose <node-id>

agent:运行 Nomad 代理

启动和管理 Nomad 代理。

# 启动服务器模式
nomad agent -server
 
# 启动客户端模式
nomad agent -client
 
# 指定配置文件启动
nomad agent -config=/etc/nomad.d/

高级功能命令

acl:访问控制管理

# 创建 ACL 策略
nomad acl policy apply -description "Dev team policy" dev-policy policy.hcl
 
# 创建 ACL 令牌
nomad acl token create -name="dev-token" -policy=dev-policy
 
# 列出所有策略
nomad acl policy list

deployment:部署管理

# 列出部署
nomad deployment list
 
# 暂停部署
nomad deployment pause <deployment-id>
 
# 恢复部署
nomad deployment resume <deployment-id>

namespace:命名空间管理

# 创建命名空间
nomad namespace apply -description "Development environment" development
 
# 列出所有命名空间
nomad namespace list
 
# 删除命名空间
nomad namespace delete development

operator:运维工具

# 创建快照
nomad operator snapshot save backup.snap
 
# 恢复快照
nomad operator snapshot restore backup.snap
 
# 查看调度器配置
nomad operator scheduler get-config

scaling:扩缩容管理

# 列出扩缩容策略
nomad scaling policy list
 
# 查看某个策略的详情
nomad scaling policy info <policy-id>
 
# 手动调整任务组实例数
nomad job scale nginx nginx 5

volume:存储卷管理

# 创建卷
nomad volume create volume.hcl
 
# 列出所有卷
nomad volume status
 
# 删除卷
nomad volume delete <volume-id>

辅助工具命令

ui:Web 界面访问

# 打开 Web 界面
nomad ui
 
# 指定地址打开 Web 界面
nomad ui -address=http://nomad.example.com

fmt:配置文件格式化

# 格式化单个文件
nomad fmt job.hcl
 
# 格式化目录下所有文件
nomad fmt ./jobs/
 
# 检查格式但不修改
nomad fmt -check job.hcl

tls:TLS 证书管理

# 生成 CA 证书
nomad tls ca create
 
# 生成服务器证书
nomad tls cert create -server
 
# 生成客户端证书
nomad tls cert create -client

nginx 作业配置文件示例

# nginx.job.hcl
# 作业定义
job "nginx" {
  # 指定数据中心
  datacenters = ["dc1"]
 
  # 指定作业类型:service(长期运行), batch(一次性), system(每个节点运行一个)
  type = "service"
 
  # 更新策略
  update {
    max_parallel      = 1
    min_healthy_time  = "10s"
    healthy_deadline  = "3m"
    progress_deadline = "10m"
    auto_revert       = false
    canary            = 0
  }
 
  # 分组定义
  group "nginx" {
    # 期望运行的实例数量
    count = 3
 
    # 网络定义
    network {
      port "http" {
        static = 80
        to     = 80
      }
    }
 
    # 服务注册配置
    service {
      name = "nginx"
      tags = ["web", "nginx"]
      port = "http"
 
      check {
        type     = "http"
        path     = "/"
        interval = "10s"
        timeout  = "2s"
      }
    }
 
    # 重启策略
    restart {
      attempts = 2
      interval = "30m"
      delay    = "15s"
      mode     = "fail"
    }
 
    # Task 定义
    task "nginx" {
      # 使用 docker 驱动
      driver = "docker"
 
      # docker 配置
      config {
        image = "nginx:latest"
        ports = ["http"]
 
        # 挂载自定义配置文件
        volumes = [
          "local/nginx.conf:/etc/nginx/nginx.conf"
        ]
      }
 
      # 资源限制
      resources {
        cpu    = 500 # 500 MHz
        memory = 256 # 256MB
      }
 
      # 环境变量
      env {
        NGINX_PORT = "80"
      }
 
      # 模板配置(使用 consul-template 语法)
      template {
        data = <<EOF
events {
    worker_connections 1024;
}
 
http {
    upstream backend {
        server 127.0.0.1:8080;
    }
 
    server {
        listen {{ env "NGINX_PORT" }};
        server_name localhost;
 
        location / {
            proxy_pass http://backend;
            proxy_set_header Host $host;
            proxy_set_header X-Real-IP $remote_addr;
        }
    }
}
EOF
        destination   = "local/nginx.conf"
        change_mode   = "signal"
        change_signal = "SIGHUP"
      }
    }
  }
}

结语

Nomad 作为一个轻量级的容器编排平台,以其简单性、灵活性和可靠性赢得了不少用户的青睐。对于那些想要一个简单但功能强大的容器编排解决方案的组织来说,Nomad 是一个值得考虑的选择。

尽管它可能不如 Kubernetes 那样拥有庞大的生态系统,但在特定的使用场景下,Nomad 的优势可能会更加明显。选择合适的工具需要根据具体的需求和场景来决定,没有一种解决方案能够适合所有情况。