NomployNomploy

Architecture of Nomploy

How Nomploy orchestrates deployments with Nomad, Consul, Traefik and WireGuard.

Nomploy is a control layer on top of HashiCorp Nomad and Consul. It keeps the familiar panel, Git integration, domains, backups and monitoring, but uses Nomad for orchestration instead of Docker Swarm — giving you HCL jobspecs, native Nomad Packs and multi-node scheduling.

Core components

  • Nomad — orchestrates every workload (applications, databases, services) as a job.
  • Consul — service discovery, health checks and configuration (KV); it feeds routing data to Traefik.
  • Traefik — the edge router. It builds routes automatically from the Consul Catalog and issues Let's Encrypt TLS certificates.
  • Postgres + Redis — store the panel's state and job queues on the control plane.
  • WireGuard — an encrypted 10.10.0.0/24 overlay that binds all nodes together.
  • The panel — Nomploy itself runs as a self-updating Nomad job.

Control plane vs. workers

The first node is the hub (control plane). It runs:

  • The Nomploy panel, backed by Postgres and Redis
  • A Traefik instance
  • The Nomad server and Consul server (the scheduling layer)
  • A Nomad client, so the hub can run workloads too

This node carries the Nomad meta tag nomploy_control_plane = "true", which pins the panel to run only there. Worker nodes don't have this tag — they run only Nomad and Consul clients and execute the workloads scheduled onto them.

High availability here means the scheduler / control plane survives server failures. The panel and its database currently run on a single node.

Networking & service discovery

Every node joins the WireGuard mesh, with addresses assigned by role:

  • .1 — hub (control plane)
  • .1–.10 — servers
  • .11+ — workers

Nomad and Consul bind to the overlay interface (wg0), so all cluster traffic is encrypted. Workers peer directly with every server, so scheduling continues even if the hub goes down. Each server also runs a DNS resolver for Consul service names (<service>.service.consul).

How deployments flow

Workloads become Nomad jobs through three paths:

  1. Applications & databases render from the panel's settings.
  2. Docker Compose files are translated into equivalent Nomad jobspecs.
  3. Native Nomad HCL or Nomad Packs deploy verbatim.

Traefik picks up each new service from the Consul Catalog and starts routing traffic to it, with automatic HTTPS via Let's Encrypt.

Self-updates

Because the panel is itself a Nomad job, it performs rolling updates with force_pull, comparing the running image digest against the registry tag to detect new versions.

Scaling out

To add capacity, join more nodes into the WireGuard mesh as servers or workers. See Cluster for multi-node setup and Installation to get started.

On this page