Source commit: e570b80c3a0f4b152a9aa0e7bb8635b3eebcec27 Public tree identity: sha256:cff3388143eb2e9476804cfa1c1246e3a46d485d8aef90f2cdd4df45f2b69abf
1.5 KiB
Self-hosting
Run the public coordinator and node runtime without the hosted website.
Start a strict local coordinator
Supply one scoped bootstrap session through protected service configuration:
CLUSTERFLUX_SELF_HOSTED_SESSION_SECRET="$SELF_HOSTED_SESSION_SECRET" CLUSTERFLUX_SELF_HOSTED_TENANT=my-team CLUSTERFLUX_SELF_HOSTED_PROJECT=my-project CLUSTERFLUX_SELF_HOSTED_USER=me clusterflux-coordinator --listen 127.0.0.1:7999
Connect the CLI without placing the secret in a process argument:
printf '%s\n' "$SELF_HOSTED_SESSION_SECRET" | clusterflux auth connect-self-hosted --coordinator 127.0.0.1:7999 --tenant my-team --project-id my-project --user me --session-secret-stdin
The CLI verifies the scope before writing ".clusterflux/session.json". On Unix, the session file uses mode "0600".
Attach nodes
Use the same enrollment and worker flow described in Nodes, with "--coordinator 127.0.0.1:7999".
Network boundary
The native coordinator transport is plaintext and refuses non-loopback listeners. For another machine, keep the coordinator on loopback and use an authenticated SSH tunnel or deploy a trusted TLS reverse proxy that enforces the same client boundary. Do not expose the native port directly.
Administration
Project, node, process, task, log, artifact, debug, quota, and self-hosted admin operations remain available through the public CLI/API. Authentik is one hosted identity deployment, not a requirement for your coordinator.