clusterflux-public/docs/self-hosting.md
Clusterflux release 2927ca6912 Public release release-ce2d9c9dc397
Source commit: ce2d9c9dc3979543dd4e40b29e7fba2d55cc8633

Public tree identity: sha256:168e259dfbcbf75b34d46c1c641fd448e474550988c1d2eda802826bf103c0bc
2026-07-19 13:31:53 +02:00

1.5 KiB

Self-hosting

Run the public coordinator and node runtime without the hosted website.

Start a strict local coordinator

Supply one scoped bootstrap session through protected service configuration:

CLUSTERFLUX_SELF_HOSTED_SESSION_SECRET="$SELF_HOSTED_SESSION_SECRET" CLUSTERFLUX_SELF_HOSTED_TENANT=my-team CLUSTERFLUX_SELF_HOSTED_PROJECT=my-project CLUSTERFLUX_SELF_HOSTED_USER=me clusterflux-coordinator --listen 127.0.0.1:7999

Connect the CLI without placing the secret in a process argument:

printf '%s\n' "$SELF_HOSTED_SESSION_SECRET" | clusterflux auth connect-self-hosted   --coordinator 127.0.0.1:7999   --tenant my-team   --project-id my-project   --user me   --session-secret-stdin

The CLI verifies the scope before writing ".clusterflux/session.json". On Unix, the session file uses mode "0600".

Attach nodes

Use the same enrollment and worker flow described in Nodes, with "--coordinator 127.0.0.1:7999".

Network boundary

The native coordinator transport is plaintext and refuses non-loopback listeners. For another machine, keep the coordinator on loopback and use an authenticated SSH tunnel or deploy a trusted TLS reverse proxy that enforces the same client boundary. Do not expose the native port directly.

Administration

Project, node, process, task, log, artifact, debug, quota, and self-hosted admin operations remain available through the public CLI/API. Authentik is one hosted identity deployment, not a requirement for your coordinator.