Cluster
Cluster
Managers, workers, and how nodes form a Cellar cluster
A Cellar cluster is one or more managers plus optional workers.
- Managers are Raft voters. They hold replicated cluster state (root CA, join tokens, node records, API keys, desired sandbox state). The Raft leader signs certificates, accepts writes, and schedules sandboxes.
- Workers do not vote. They heartbeat to a manager and run the sandboxes assigned to them.
One manager is enough to start. Add workers for capacity, and more managers (an odd count) when you want Raft quorum across hosts. Both roles can run sandboxes — role is about the control plane, not whether the host has a VM runtime.
Standing up nodes
- Install Cellar and start
cellardon each host (quick start or install). - On the first host, run
cellar initwith a reachable--advertise-addr. - On later hosts,
cellar joinwith a worker or manager token fromcellar join-token.
Ports between nodes
Intra-cluster traffic uses real node-reachable addresses — not a public load balancer:
| Listener | Default | Who listens |
|---|---|---|
| Remote gRPC | :17946 | Every joined node |
| Raft TCP | :17947 | Managers only |
Put an Application Load Balancer in front of cellar-gateway only. Keep Raft and gRPC advertise addresses as private IPs that peers can dial.
For binaries, roles, and the cluster CA, see Architecture. To list, promote, demote, or drain nodes after join, see Manage nodes.