Architecture of Nomploy
How Nomploy orchestrates deployments with Nomad, Consul, Traefik and WireGuard.
Nomploy is a control layer on top of HashiCorp Nomad and Consul. It keeps the familiar panel, Git integration, domains, backups and monitoring, but uses Nomad for orchestration instead of Docker Swarm — giving you HCL jobspecs, native Nomad Packs and multi-node scheduling.
Core components
- Nomad — orchestrates every workload (applications, databases, services) as a job.
- Consul — service discovery, health checks and configuration (KV); it feeds routing data to Traefik.
- Traefik — the edge router. It builds routes automatically from the Consul Catalog and issues Let's Encrypt TLS certificates.
- Postgres + Redis — store the panel's state and job queues on the control plane.
- WireGuard — an encrypted
10.10.0.0/24overlay that binds all nodes together. - The panel — Nomploy itself runs as a self-updating Nomad job.
Control plane vs. workers
The first node is the hub (control plane). It runs:
- The Nomploy panel, backed by Postgres and Redis
- A Traefik instance
- The Nomad server and Consul server (the scheduling layer)
- A Nomad client, so the hub can run workloads too
This node carries the Nomad meta tag nomploy_control_plane = "true", which pins
the panel to run only there. Worker nodes don't have this tag — they run only
Nomad and Consul clients and execute the workloads scheduled onto them.
High availability here means the scheduler / control plane survives server failures. The panel and its database currently run on a single node.
Networking & service discovery
Every node joins the WireGuard mesh, with addresses assigned by role:
.1— hub (control plane).1–.10— servers.11+— workers
Nomad and Consul bind to the overlay interface (wg0), so all cluster traffic is
encrypted. Workers peer directly with every server, so scheduling continues even
if the hub goes down. Each server also runs a DNS resolver for Consul service
names (<service>.service.consul).
How deployments flow
Workloads become Nomad jobs through three paths:
- Applications & databases render from the panel's settings.
- Docker Compose files are translated into equivalent Nomad jobspecs.
- Native Nomad HCL or Nomad Packs deploy verbatim.
Traefik picks up each new service from the Consul Catalog and starts routing traffic to it, with automatic HTTPS via Let's Encrypt.
Self-updates
Because the panel is itself a Nomad job, it performs rolling updates with
force_pull, comparing the running image digest against the registry tag to
detect new versions.
Scaling out
To add capacity, join more nodes into the WireGuard mesh as servers or workers. See Cluster for multi-node setup and Installation to get started.