mirror of
https://github.com/fosrl/docs-v2.git
synced 2026-10-04 11:49:07 +02:00
Add clustering deployment guidelines
This commit is contained in:
-2
@@ -31,9 +31,7 @@ Throughout this guide, replace the following placeholders with your own values:
|
||||
| `LOAD_BALANCER_IP` | IP address of the load balancer in front of the cluster |
|
||||
| `pangolin.example.com` | Your dashboard domain - DNS points at the load balancer, not at either node |
|
||||
|
||||
<Warning>
|
||||
You need a domain for the Pangolin UI and API (`pangolin.example.com` in this guide), pointed at your load balancer. **The load balancer is responsible for TLS on this domain** - terminate HTTPS there and forward plain HTTP to the nodes' dashboard port. The nodes' built-in ACME client only issues certificates for resource domains under the delegated nameserver zone, not for the dashboard domain itself. See [Requirements](/self-host/advanced/clustering/requirements#dashboard-domain).
|
||||
</Warning>
|
||||
|
||||
<Steps>
|
||||
|
||||
@@ -35,11 +35,9 @@ For sizing information, see [Choosing a VPS](/self-host/choosing-a-vps) - the sa
|
||||
|
||||
You also need a domain for the Pangolin UI and API itself (e.g. `pangolin.example.com`) - this is separate from the nameserver domain above, which is the nameserver to resolve resource DNS.
|
||||
|
||||
<Warning>
|
||||
Point this domain's DNS record at your **load balancer**, not at either node directly. The load balancer is also responsible for obtaining and serving the TLS certificate for this domain - the nodes' built-in ACME client only issues certificates for resource domains under the delegated nameserver zone, not for the dashboard domain. Terminate TLS at the load balancer and forward plain HTTP to the nodes.
|
||||
|
||||
You must also set this domain as `app.dashboard_url` and add it to `server.cors.origins` in every node's `config.yml`. See [Deploy a Cluster](/self-host/advanced/clustering/deploy-a-cluster).
|
||||
</Warning>
|
||||
|
||||
### Required Ports
|
||||
|
||||
+6
-38
@@ -15,44 +15,12 @@ In a clustered configuration, multiple Pangolin instances operate together, shar
|
||||
|
||||
A Pangolin cluster consists of several coordinated components that work together to provide high availability and seamless failover.
|
||||
|
||||
```mermaid
|
||||
flowchart TB
|
||||
Users(["Users / Browsers"])
|
||||
Sites(["Site Connectors (Newt)"])
|
||||
|
||||
LB["Load Balancer<br/>(your own)<br/>TCP 80 · 443 · 3000 · UDP 53"]
|
||||
|
||||
subgraph Node1["Node 1"]
|
||||
direction TB
|
||||
G1["Gerbil<br/>WireGuard + SNI proxy"]
|
||||
T1["Traefik<br/>TLS termination"]
|
||||
P1["Pangolin<br/>UI · API · DNS · ACME client"]
|
||||
G1 --- T1 --- P1
|
||||
end
|
||||
|
||||
subgraph Node2["Node 2"]
|
||||
direction TB
|
||||
G2["Gerbil<br/>WireGuard + SNI proxy"]
|
||||
T2["Traefik<br/>TLS termination"]
|
||||
P2["Pangolin<br/>UI · API · DNS"]
|
||||
G2 --- T2 --- P2
|
||||
end
|
||||
|
||||
PG[("PostgreSQL<br/>shared state + certs")]
|
||||
RD[("Valkey / Redis<br/>pub/sub + sessions")]
|
||||
|
||||
Users --> LB
|
||||
LB --> G1
|
||||
LB --> G2
|
||||
Sites -. WireGuard tunnel .-> G1
|
||||
Sites -. WireGuard tunnel .-> G2
|
||||
G1 <-. cross-node request routing .-> G2
|
||||
|
||||
P1 <--> PG
|
||||
P2 <--> PG
|
||||
P1 <--> RD
|
||||
P2 <--> RD
|
||||
```
|
||||
<Frame>
|
||||
<img
|
||||
src="/images/ha-deployment-diagram.png"
|
||||
alt="Diagram showing the cluster deployment"
|
||||
/>
|
||||
</Frame>
|
||||
|
||||
### Pangolin Instances
|
||||
|
||||
Reference in New Issue
Block a user