Servers
Adding servers
One server is a complete Jokku. Add another with one command and apps spread across both.
Add a server#
Ask the first server for a join command:
It prints a one-liner. Run it on the new server, which needs the same requirements as the first:
The servers connect over an encrypted private network (WireGuard on UDP 51820; the first server also needs TCP 7443 open for joining). Apps are spread across all of them, and every server can receive web traffic, so point your DNS at as many as you like.
A join command works for an hour and adds one server. For autoscaling, make one that adds any number of servers until it expires, and put it in your cloud-init user-data:
The control server#
The first server is the control server. It holds the cluster's state, builds your apps and receives your git push and SSH commands. It also runs apps, like every other server.
The others are workers. They run apps and serve traffic, and hold no state of their own: wipe one and join it again, and it picks up where it left off.
Where apps run#
When an instance needs a home, Jokku picks a server that is up, has the memory free, and runs the fewest instances of that same process. So ps:scale myapp web=3 on three servers puts one on each.
When a server dies#
- After 30 seconds without a report, it's marked
down, and the proxies stop sending it requests. - After another minute, so that reboots and updates don't shuffle anything, its instances are started on the other servers.
- When it comes back, it stops the instances that have moved.
The proxy gives up on an unreachable instance after two seconds and retries the request on another, for up to five seconds. Apps with volumes on a dead server wait for it to come back, because their data is there. To bring them up elsewhere, restore their latest backup onto another server.
Maintenance#
To take a server out for maintenance, drain it first:
Draining starts a copy of each instance elsewhere, waits for it to pass checks, then stops the original, so traffic never drops. Instances with volumes move with their disks, which costs a short stop.
To take a server out of the cluster for good:
nodes:remove refuses while the server holds volumes. --force skips the drain and treats the server as dead, losing any volumes on it.