Nomad Single Server, A Variable Round-Tripped
HashiCorp Nomad as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, RPC and serf on loopback, an explicit advertise block (Nomad refuses to start without one) and its configuration checked by nomad config validate. The live test waits for a leader and round-trips a variable with nomad var. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify
Documentation
nomad-server
HashiCorp Nomad as a single-node server from the upstream release
(sha256-verified), as a hardened system service with HTTP, RPC and serf on
loopback and its configuration checked by nomad config validate before it
lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No package, so the checksum is the whole story. EL 10 carries no
nomad; HashiCorp ships a release with a checksum file beside it. The
role downloads both and has Ansible's get_url refuse the asset unless its
SHA-256 is the one in the vendor's file, then installs the binaries as
root's in /usr/local/bin, pinned by nomad_server_version.
A service account, a hardened unit, a loopback listener. nomad
is a system user with no shell that owns the data directory and nothing
else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and
ProtectSystem=strict. The listener is 127.0.0.1:4646 by default,
for a proxy that authenticates or a client on the same host; the live test
reads the listening sockets and expects loopback only.
A server that schedules nothing yet. The client is off: running
workloads needs privileges (cgroups, namespaces, a task driver) the
hardened unit does not grant, and a client is a role of its own. The
server alone elects itself leader, holds the state and the variables
store, and the live test proves that: it waits for a leader, writes a
variable with nomad var put, reads it back, purges it, and reads
nomad server members as one alive leader.
The advertise block is not optional on loopback. Nomad refuses to
start when its advertise address would default to localhost; the role
writes advertise { http rpc serf } from the bind address, and Nomad
prints a warning that mTLS is not configured, which is true until you
put certificates in nomad_server_extra_config.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test