Add clustering deployment guidelines

This commit is contained in:
Owen
2026-09-11 15:49:47 -04:00
parent 2904fa44f6
commit 79f584ee24
8 changed files with 34 additions and 63 deletions
@@ -31,9 +31,7 @@ Throughout this guide, replace the following placeholders with your own values:
| `LOAD_BALANCER_IP` | IP address of the load balancer in front of the cluster |
| `pangolin.example.com` | Your dashboard domain - DNS points at the load balancer, not at either node |
<Warning>
You need a domain for the Pangolin UI and API (`pangolin.example.com` in this guide), pointed at your load balancer. **The load balancer is responsible for TLS on this domain** - terminate HTTPS there and forward plain HTTP to the nodes' dashboard port. The nodes' built-in ACME client only issues certificates for resource domains under the delegated nameserver zone, not for the dashboard domain itself. See [Requirements](/self-host/advanced/clustering/requirements#dashboard-domain).
</Warning>
<Steps>
@@ -35,11 +35,9 @@ For sizing information, see [Choosing a VPS](/self-host/choosing-a-vps) - the sa
You also need a domain for the Pangolin UI and API itself (e.g. `pangolin.example.com`) - this is separate from the nameserver domain above, which is the nameserver to resolve resource DNS.
<Warning>
Point this domain's DNS record at your **load balancer**, not at either node directly. The load balancer is also responsible for obtaining and serving the TLS certificate for this domain - the nodes' built-in ACME client only issues certificates for resource domains under the delegated nameserver zone, not for the dashboard domain. Terminate TLS at the load balancer and forward plain HTTP to the nodes.
You must also set this domain as `app.dashboard_url` and add it to `server.cors.origins` in every node's `config.yml`. See [Deploy a Cluster](/self-host/advanced/clustering/deploy-a-cluster).
</Warning>
### Required Ports
@@ -15,44 +15,12 @@ In a clustered configuration, multiple Pangolin instances operate together, shar
A Pangolin cluster consists of several coordinated components that work together to provide high availability and seamless failover.
```mermaid
flowchart TB
Users(["Users / Browsers"])
Sites(["Site Connectors (Newt)"])
LB["Load Balancer<br/>(your own)<br/>TCP 80 · 443 · 3000 · UDP 53"]
subgraph Node1["Node 1"]
direction TB
G1["Gerbil<br/>WireGuard + SNI proxy"]
T1["Traefik<br/>TLS termination"]
P1["Pangolin<br/>UI · API · DNS · ACME client"]
G1 --- T1 --- P1
end
subgraph Node2["Node 2"]
direction TB
G2["Gerbil<br/>WireGuard + SNI proxy"]
T2["Traefik<br/>TLS termination"]
P2["Pangolin<br/>UI · API · DNS"]
G2 --- T2 --- P2
end
PG[("PostgreSQL<br/>shared state + certs")]
RD[("Valkey / Redis<br/>pub/sub + sessions")]
Users --> LB
LB --> G1
LB --> G2
Sites -. WireGuard tunnel .-> G1
Sites -. WireGuard tunnel .-> G2
G1 <-. cross-node request routing .-> G2
P1 <--> PG
P2 <--> PG
P1 <--> RD
P2 <--> RD
```
<Frame>
<img
src="/images/ha-deployment-diagram.png"
alt="Diagram showing the cluster deployment"
/>
</Frame>
### Pangolin Instances