hashicorp / hashicorp/nomad

Client Auto-Config

Open
#16,574 1 comment 16 reactions 0 assignees View on GitHub
theme/node-identity type/enhancement
Dominant language
Go
Stars
17k
Forks
2.1k
Avg merge
1d 9h
Merged PRs (30d)
105

Description

### Proposal

Consul has an [Auto-Config feature](https://www.hashicorp.com/blog/automate-consul-agent-security-with-auto-config) which allows Consul clients to automatically configure TLS without having to manually manage certs and config files.

In addition to TLS config, other [Nomad client config](https://developer.hashicorp.com/nomad/docs/configuration) values could be sent to clients via some centralized way.

More research and exploration is needed, but opening this ticket now in case people have ideas, feedback on how Consul's auto config is working, or any other thoughts.

### Use-cases

Remove complexity from the process of security Nomad:
- Reduce chance of churning during Nomad set up process
- Reduce chances of an insecure Nomad cluster going to prod
- Reduce necessity of configuration management tooling for client config

### Feedback

I am actively looking to discuss this with potential users, so if you would like to chat about client config, pleas book a 30 minute slot using [this link](https://calendly.com/mnomitch/roadmap-chat) or send an email to mnomitch@hashicorp.com

Contributor guide

No contributing guide indexed for this repository

Research direction

No files, tests, or entry points are identified. Start by reviewing the linked Consul Auto-Config feature and Nomad client configuration documentation, then use the stated feedback channels to define a concrete scope; done requires an agreed design and implementation plan.

Written by the indexing model from the issue text.

Assessment

Domain
infrastructure, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.