Nomad Single Server, A Variable Round-Tripped

HashiCorp Nomad as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, RPC and serf on loopback, an explicit advertise block (Nomad refuses to start without one) and its configuration checked by nomad config validate. The live test waits for a leader and round-trips a variable with nomad var. Original role, live-tested on Rocky Linux 10.

ansibleCompute & VMs

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-09-20 · podman 4.9.3 · ansible 2.21.4 · how we verify

Documentation

nomad-server

HashiCorp Nomad as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, RPC and serf on loopback and its configuration checked by nomad config validate before it lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No package, so the checksum is the whole story. EL 10 carries no nomad; HashiCorp ships a release with a checksum file beside it. The role downloads both and has Ansible's get_url refuse the asset unless its SHA-256 is the one in the vendor's file, then installs the binaries as root's in /usr/local/bin, pinned by nomad_server_version.

A service account, a hardened unit, a loopback listener. nomad is a system user with no shell that owns the data directory and nothing else; the unit runs with NoNewPrivileges, PrivateTmp, ProtectHome and ProtectSystem=strict. The listener is 127.0.0.1:4646 by default, for a proxy that authenticates or a client on the same host; the live test reads the listening sockets and expects loopback only.

A server that schedules nothing yet. The client is off: running workloads needs privileges (cgroups, namespaces, a task driver) the hardened unit does not grant, and a client is a role of its own. The server alone elects itself leader, holds the state and the variables store, and the live test proves that: it waits for a leader, writes a variable with nomad var put, reads it back, purges it, and reads nomad server members as one alive leader.

The advertise block is not optional on loopback. Nomad refuses to start when its advertise address would default to localhost; the role writes advertise { http rpc serf } from the bind address, and Nomad prints a warning that mTLS is not configured, which is true until you put certificates in nomad_server_extra_config.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules