High availability
[!NOTE] Clustering needs a valid license on every node. Several NullWard nodes can run as one cluster. Each node keeps its own SurrealDB and Valkey. There's no shared database. Nodes exchange configuration, blocks and certificates with each other over an encrypted WireGuard mesh. A change made in the dashboard of any node reaches all the others. Requests never wait for another node. If nodes lose contact, each keeps serving with what it has and catches up when the connection returns. Put the nodes behind a load balancer or DNS that spreads traffic across them. Before you start Deploy each node as described in Deploy with Docker Compose, with its own SurrealDB and Valkey. Give every node the same NULLWARD_ENCRYPTION_KEY and NULLWARD_JWT_SECRET. Each node can have its own admin password. The bootstrap admin account is local to each node. Activate a license on every node. Allow UDP 7057 (the mesh port) between the nodes, and publish it in Docker Compose ("7057:7057/udp"). Gossip and file transfer run inside the encrypted mesh and need no other firewall rules. Set up the cluster On each node, go to Administration > Cluster. Open Cluster Configuration and turn on clustering. Set Advertise Address: the address and port other nodes use to reach this node's mesh port, for example waf1.example.com:7057. Set Public Admin URL, and choose a Network Profile: LAN (low latency, fast failure detection) or WAN (high-latency links, slower detection). The mesh range and ports can usually stay at their defaults. Click Save Settings, then restart the node. Cluster settings take effect after a restart. Then join the nodes together: On the first node, click Generate Join Token and choose how long the token is valid. On each other node, click Join Cluster and paste the token. [!WARNING] Joining replaces the joining node's shared configuration with the cluster's. Join new, empty nodes to the node that holds your configuration. The Cluster page shows each member and its health. Event pages such as WAF events and the audit log gain a node filter. Certificates in a cluster Any node may renew a certificate, so use the DNS-01 challenge for ACME in a cluster. See TLS certificates. By default each certificate's renewal node is chosen automatically, and another node takes over if it goes down. You can pin a renewal node per service.
NullWard documentation