CellarCellar
Cluster

Cluster

Managers, workers, and how nodes form a Cellar cluster

A Cellar cluster is one or more managers plus optional workers.

  • Managers are Raft voters. They hold replicated cluster state (root CA, join tokens, node records, API keys, desired sandbox state). The Raft leader signs certificates, accepts writes, and schedules sandboxes.
  • Workers do not vote. They heartbeat to a manager and run the sandboxes assigned to them.

One manager is enough to start. Add workers for capacity, and more managers (an odd count) when you want Raft quorum across hosts. Both roles can run sandboxes — role is about the control plane, not whether the host has a VM runtime.

Standing up nodes

  1. Install Cellar and start cellard on each host (quick start or install).
  2. On the first host, run cellar init with a reachable --advertise-addr.
  3. On later hosts, cellar join with a worker or manager token from cellar join-token.

Ports between nodes

Intra-cluster traffic uses real node-reachable addresses — not a public load balancer:

ListenerDefaultWho listens
Remote gRPC:17946Every joined node
Raft TCP:17947Managers only

Put an Application Load Balancer in front of cellar-gateway only. Keep Raft and gRPC advertise addresses as private IPs that peers can dial.

For binaries, roles, and the cluster CA, see Architecture. To list, promote, demote, or drain nodes after join, see Manage nodes.

On this page