Advanced Topics
Rolling updates, multi-arch, init systems, build from source.
Rolling Updates
Section titled “Rolling Updates”SwarmCracker supports zero-downtime rolling updates via SwarmKit orchestration.
How It Works
Section titled “How It Works”- Manager creates new task with updated spec
- SwarmCracker starts new Firecracker VM
- VM reports RUNNING status
- Manager waits for Monitor period (default: 5s)
- Manager stops old task
- Executor removes old VM
Update a Service
Section titled “Update a Service”# Update image (triggers rolling update)swarmctl update svc-nginx --image nginx:1.25
# Update with environmentswarmctl update svc-app --env LOG_LEVEL=debugConfiguration
Section titled “Configuration”SwarmKit controls update behavior (not SwarmCracker):
| Parameter | Default | Description |
|---|---|---|
| Parallelism | 1 | Tasks updated simultaneously |
| Delay | 0s | Wait between batches |
| Monitor | 5s | Verify task stability |
| Failure Action | pause | On failure: pause/continue/rollback |
Multi-Architecture Support
Section titled “Multi-Architecture Support”SwarmCracker supports multiple CPU architectures via placement constraints.
Supported Architectures
Section titled “Supported Architectures”| Arch | Firecracker Support | Notes |
|---|---|---|
| x86_64 | ✅ Full support | Primary target |
| arm64 | ✅ Experimental | AWS Graviton, Ampere |
Architecture Constraints
Section titled “Architecture Constraints”# Create service constrained to x86_64 nodesswarmctl create-service nginx:latest --constraint arch==x86_64
# Create service constrained to arm64 nodesswarmctl create-service arm-app:latest --constraint arch==arm64Multi-Arch Images
Section titled “Multi-Arch Images”Use OCI image indexes for cross-arch compatibility:
# Build multi-arch imagedocker buildx build --platform linux/amd64,linux/arm64 -t myapp:latest .
# SwarmCracker pulls correct variant based on node archInit Systems
Section titled “Init Systems”MicroVMs need an init system for proper process management.
Why Init Matters
Section titled “Why Init Matters”- Zombie reaping — Orphan processes must be reaped
- Signal handling — Forward SIGTERM to children
- Process supervision — Restart failed processes
Supported Init Systems
Section titled “Supported Init Systems”| Init | Size | Features |
|---|---|---|
| tini | ~20KB | Minimal, Docker default |
| dumb-init | ~30KB | Signal proxy, lightweight |
| s6 | ~100KB | Process supervision |
| systemd | Large | Full service management |
Configure Init
Section titled “Configure Init”executor: init_system: tini # none | tini | dumb-init init_grace_period: 10 # seconds before SIGKILL during shutdownRootfs with Init
Section titled “Rootfs with Init”# Install tini in rootfscurl -fsSL https://github.com/krallin/tini/releases/download/v0.19.0/tini-static -o rootfs/sbin/tinichmod +x rootfs/sbin/tiniBuild from Source
Section titled “Build from Source”Prerequisites
Section titled “Prerequisites”- Go 1.26+
- Git
- Make
Clone and Build
Section titled “Clone and Build”# Clone repositorygit clone https://github.com/restuhaqza/SwarmCrackercd SwarmCracker
# Build binariesmake all
# Output:# build/swarmcracker# build/swarmd-firecracker# build/swarmcracker-agent
# Installsudo make installBuild Targets
Section titled “Build Targets”make all # Build all binariesmake swarmcracker # Build the main CLImake test # Run unit testsmake lint # Run lintersmake fmt # Format codemake clean # Clean build artifactsmake install # Install binaries to $GOPATH/binDevelopment Build
Section titled “Development Build”# Build a debug/dev binarygo build -o build/swarmcracker ./cmd/swarmcracker
# Run the CLI./build/swarmcracker --helpsystemd Services
Section titled “systemd Services”swarmcracker cluster init (manager) and swarmcracker cluster join (worker)
generate and enable the systemd units for you:
swarmcracker-manager.service— runsswarmd-firecracker --manageron the managerswarmcracker-worker.service— runsswarmd-firecrackeron workers
Inspect and control them with systemd:
sudo systemctl status swarmcracker-managersudo systemctl restart swarmcracker-worker
# Logssudo journalctl -u swarmcracker-manager -fsudo journalctl -u swarmcracker-worker -fThere is no standalone swarmcracker service.
File Management
Section titled “File Management”Manage rootfs and kernel images.
Rootfs Directory
Section titled “Rootfs Directory”executor: rootfs_dir: "/var/lib/firecracker/rootfs"Kernel Management
Section titled “Kernel Management”executor: kernel_path: "/usr/share/firecracker/vmlinux"Image Storage
Section titled “Image Storage”/var/lib/firecracker/├── rootfs/ # executor.rootfs_dir│ ├── nginx-rootfs.ext4│ └── redis-rootfs.ext4└── golden/ # prebuilt golden image artifacts
/usr/share/firecracker/└── vmlinux # executor.kernel_path (default kernel)Troubleshooting
Section titled “Troubleshooting”Rolling Update Stuck
Section titled “Rolling Update Stuck”# Check task statusswarmctl ls-tasks
# Check node availabilityswarmctl ls-nodes
# Force rollback if neededswarmctl update <service-id> --image nginx:1.25-alpineInit Process Missing
Section titled “Init Process Missing”# Check init in rootfsls rootfs/sbin/tini
# Verify init binaryfile rootfs/sbin/tiniBuild Fails
Section titled “Build Fails”# Check Go versiongo version # Must be 1.26+
# Check dependenciesgo mod download
# Run lint for errorsmake lintSee Also: Configuration | Contributing Guide