More servers
Adding one
Add Server in the console: give the server's name, IP and SSH user, confirm its host key fingerprint and authorize a temporary key (or paste your own). Orbit runs the same checks and plan as on the first machine and, after you approve it, joins the server to the cluster as a K3s agent with its own Orbit agent. New services can then be placed on it.
More servers add room, not high availability
A service runs on the server you choose and stops if that server stops, unless it is an application spread across servers or a database with PostgreSQL replicas. Traffic enters through the main server, so domains keep pointing to it.
Network requirements
- Every server must reach the main server's IPv4 on TCP 6443 (Kubernetes) and 7443 (Orbit's agents).
- The main server must reach every other server on TCP 10250 (logs and commands).
- All servers must reach each other on UDP 51820 (WireGuard, which encrypts traffic between servers).
- Orbit opens these on the main server for your servers only. When ufw is active on a server, Orbit allows the other servers' addresses there too. A server joined later is not added to the ufw rules of servers that joined before it: run
sudo ufw allow from <new server ip>on them.
The first join restarts K3s once on the main server to turn on WireGuard. Running applications keep running.
Builds and updates
- Builds run on the main server. An application from a repository can run on a server with the same architecture: Orbit copies its image there before each deployment.
install.shupdates Orbit and the agent of the server it runs on. Agents on added servers keep the version they were installed with.
Agents
Each server's agent reports its health and inventory over mutual TLS. A server turns offline about 90 seconds after its last heartbeat, and the console then shows its workloads as unknown.
sudo orbit revoke-agent --server srv_… # refuse that server's agent at once
sudo orbit enroll-agent --server srv_… # on the same machine: a new token, a new certificate, a restarted agentServer ids are in orbit status. Once an agent enrolls, the certificates its server had before are revoked, so only the newest enrollment is trusted.
Looking at the cluster
sudo k3s kubectl get nodes -L orbit.cortexlabs.dev/server
sudo k3s kubectl get pods -A -o wide
journalctl -u k3s-agent -f # on the other server