# IPFS Cluster How-to: please review!

**URL:** <https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074>\
**Category:** IPFS Cluster\
**Tags:** ipfs-cluster\
**Created:** [March 23, 2019, 11:47am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074 "2019-03-23T11:47:40Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [March 23, 2019, 11:47am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/1 "2019-03-23T11:47:41Z")

</div>

I found the documentation for IPFS Cluster to be inadequate for someone of my (low) skill level, so once I got a cluster working, I decided to write up what I did, in case it could help others.

I would appreciate it if anyone with more knowledge of IPFS Cluster could review and critique what I have written before I make it public. Of course, I have pinned it to my own cluster. You can find it here:

[https://gateway.ipfs.io/ipfs/QmcXuNQsPqXALRVUAnTf7B1N5dAJKU1uRPrCHvpoEBeW8V/](https://gateway.ipfs.io/ipfs/QmcXuNQsPqXALRVUAnTf7B1N5dAJKU1uRPrCHvpoEBeW8V/)

It is not pretty yet, just some basic styles to make it readable. I am more concerned about whether it is accurate at this point. Thank you!

---

<div class="post-metadata">

**Author:** ![hector](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/hector/32/178_2.png) [@hector](https://discuss.ipfs.tech/u/hector)\
**Post date:** [March 25, 2019, 1:46am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/2 "2019-03-25T01:46:34Z")

</div>

This is really nice!

My comments:

- When installing `ipfs-update` you could save the step of installing go-ipfs separately first and do it directly from `ipfs-update` (i think)
- Regarding `ctl`: `it will allow you to access cluster statistics from the command line`. I’m not sure what that means. I think you mean `interacting with your cluster daemon from the command line` ?
- For security considerations mostly, we have the convention of running `go-ipfs` and `ipfs-cluster-service` using an `ipfs` system user, rather than root. That means, the `init` commands should be run by this user and the configuration etc. are placed in `ipfs` user home. Also, in cases where your ipfs storage is an additional large disk attached to your machine, this allows you to mount the ipfs home directly on that disk.
- `The ipfs-cluster-service.service file will be very different` ? Is this the case? I don’t see differences.
- It is also important to follow things mentioned here: [https://cluster.ipfs.io/documentation/deployment/](https://cluster.ipfs.io/documentation/deployment/) or at least be familiar with the configurations options mentioned for both ipfs and cluster.

Would you mind if we include a link to this from the IPFS Cluster website once you have a final version?

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [March 25, 2019, 8:09am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/3 "2019-03-25T08:09:53Z")

</div>

Thank you! I will make these changes. Of course I’d be happy to have a link to it, once it is correct. 😀

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [March 30, 2019, 8:02pm UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/4 "2019-03-30T20:02:08Z")

</div>

I have updated it. The new version is here:

[https://gateway.ipfs.io/ipfs/QmTqD45V5EFF9DvCpr39vyJDE5m1PJYdhWSjqNdYLAgA37/](https://gateway.ipfs.io/ipfs/QmTqD45V5EFF9DvCpr39vyJDE5m1PJYdhWSjqNdYLAgA37/)

I would appreciate any further review. Thank you!

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [April 1, 2019, 9:04am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/5 "2019-04-01T09:04:18Z")

</div>

I’ve corrected some small typos for the next version, so don’t worry too much about mistakes you find like incorrect capitalization. I am more concerned with technical accuracy. Thanks!

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [April 13, 2019, 11:14am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/6 "2019-04-13T11:14:45Z")

</div>

Update:

[https://gateway.ipfs.io/ipfs/QmeVDPHgN6JMTTiJrsxhC3PEEBvcXJsLPZwwfMnwWxb6YW/](https://gateway.ipfs.io/ipfs/QmeVDPHgN6JMTTiJrsxhC3PEEBvcXJsLPZwwfMnwWxb6YW/)

That should be the last version, unless there is an error. Just cleaned up some of the text and images.

Any feedback would be very helpful!

---

<div class="post-metadata">

**Author:** ![qo-op](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/qo-op/32/1773_2.png) [@qo-op](https://discuss.ipfs.tech/u/qo-op)\
**Post date:** [April 14, 2019, 2:21pm UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/7 "2019-04-14T14:21:34Z")

</div>

Thanks for your document. I was doing kind of the same configuration… I think

- You should use ipfs specific user instead of root to run ipfs and ipfs-cluster daemons

useradd -r -s /usr/bin/nologin ipfs

```
[Unit]
Description=IPFS daemon
After=network.target

[Service]
User=ipfs
Environment="IPFS_PATH=/data/ipfs"
ExecStart=/usr/bin/ipfs daemon --mount --enable-gc --routing=dhtclient
Restart=on-failure

[Install]
WantedBy=multi-user.target

```

- Restrict disk usage on each node depending on their actual capacity

To facilitate automatic pinning by “lead” nodes… Have a look to [https://medium.com/textileio/easy-personal-ipfs-pinning-service-with-textile-9d366da4e420](https://medium.com/textileio/easy-personal-ipfs-pinning-service-with-textile-9d366da4e420)

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [April 14, 2019, 8:34pm UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/8 "2019-04-14T20:34:26Z")

</div>

So, instead of this:

```
[Unit]
Description=IPFS Daemon

[Service]
Type=simple
ExecStart=/usr/local/bin/ipfs daemon --enable-gc
Group=root
Restart=always
Environment="IPFS_PATH=/home/username/.ipfs"

[Install]
WantedBy=multi-user.target

```

I should do this?

```
[Unit]
Description=IPFS daemon
After=network.target

[Service]
User=ipfs
Environment="IPFS_PATH=/data/ipfs"
ExecStart=/usr/bin/ipfs daemon --mount --enable-gc --routing=dhtclient
Restart=on-failure

[Install]
WantedBy=multi-user.target
```

---

<div class="post-metadata">

**Author:** ![qo-op](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/qo-op/32/1773_2.png) [@qo-op](https://discuss.ipfs.tech/u/qo-op)\
**Post date:** [April 15, 2019, 8:47am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/9 "2019-04-15T08:47:28Z")

</div>

> [@dharwin](#):
>
> User=ipfs

Is better than root for system security…

> [@dharwin](#):
>
> ExecStart=/usr/bin/ipfs daemon --mount --enable-gc --routing=dhtclient

Any startup options are ok, depending on your config.  
enable-gc: activate garbage collector  
routing=dhtclient: makes node more quiet as it doesn’t maintain DHT table but use it from other node (lead)

But I am a beginner user…

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [April 15, 2019, 9:46am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/10 "2019-04-15T09:46:59Z")

</div>

Since I have already given instructions on how to create a separate user (referred to as “username”) so that root isn’t the one running IPFS, I guess this should work, yes?

```
[Unit]
Description=IPFS Daemon
After=network.target

[Service]
User=username
Environment="IPFS_PATH=/home/username/.ipfs"
ExecStart=/usr/bin/ipfs daemon --mount --enable-gc --routing=dhtclient
Restart=always

[Install]
WantedBy=multi-user.target
```

---

<div class="post-metadata">

**Author:** ![hector](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/hector/32/178_2.png) [@hector](https://discuss.ipfs.tech/u/hector)\
**Post date:** [April 15, 2019, 1:51pm UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/11 "2019-04-15T13:51:21Z")

</div>

it is customary to use a `ipfs` for username. This should be a user just for use by ipfs/cluster.

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [April 15, 2019, 8:22pm UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/12 "2019-04-15T20:22:03Z")

</div>

I’ll change the “username” to ipfs then, thanks 🙂

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [April 23, 2019, 10:06am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/13 "2019-04-23T10:06:50Z")

</div>

Updated! I hope I have it right this time:

[https://gateway.ipfs.io/ipfs/QmfXNrrqdu9WkW46gJJH1JmKjHKFhLYVg8dd71HRFWwUJs/](https://gateway.ipfs.io/ipfs/QmfXNrrqdu9WkW46gJJH1JmKjHKFhLYVg8dd71HRFWwUJs/)

---

<div class="post-metadata">

**Author:** ![hector](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/hector/32/178_2.png) [@hector](https://discuss.ipfs.tech/u/hector)\
**Post date:** [April 23, 2019, 10:49am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/14 "2019-04-23T10:49:29Z")

</div>

Hey, thanks so much. I’ll go over it when I have some time and do a final check!

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [April 23, 2019, 10:51am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/15 "2019-04-23T10:51:30Z")

</div>

Thank you! I am looking forward to getting it published if it is ready.

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [May 7, 2019, 2:42pm UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/16 "2019-05-07T14:42:02Z")

</div>

Does this look good to go? I want to publish it before anything changes that makes it need updating 🙂

---

<div class="post-metadata">

**Author:** ![hector](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/hector/32/178_2.png) [@hector](https://discuss.ipfs.tech/u/hector)\
**Post date:** [May 8, 2019, 10:22am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/17 "2019-05-08T10:22:41Z")

</div>

Thanks for the ping. I can’t load it up though 😕

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [May 8, 2019, 10:33am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/18 "2019-05-08T10:33:57Z")

</div>

Thanks, I’ll check it…

---

<div class="post-metadata">

**Author:** ![dharwin](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/dharwin/32/1718_2.png) [@dharwin](https://discuss.ipfs.tech/u/dharwin)\
**Post date:** [May 8, 2019, 10:52am UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/19 "2019-05-08T10:52:50Z")

</div>

I can’t get it either. IPFS is running on my remote server, and the hash is right. I am adding it to a local IPFS instance as well, maybe that will help.

In the meantime, here it is as just a regular webpage:

[http://ul-qoma.com/IPFS\_Cluster\_Articlev3/](http://ul-qoma.com/IPFS_Cluster_Articlev3/)

Thanks!

---

<div class="post-metadata">

**Author:** ![hector](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ipfs.tech/hector/32/178_2.png) [@hector](https://discuss.ipfs.tech/u/hector)\
**Post date:** [May 8, 2019, 12:34pm UTC](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074/20 "2019-05-08T12:34:44Z")

</div>

- `Build a 4 continent IPFS Cluster` -\> `Build a 4-continent` though it reads weird. Maybe `Build an IPFS Cluster spawning 4 continents...` is better.

- `Bootstrap the additional nodes to the join the cluster` -\> `bootstrap additional IPFS Cluster peers to join the cluster`.

- Regarding the ipfs user, best practice would be to not use it to log in (instead login to some other user and switch to it -`su - ipfs`- or sudo -`sudo -u ipfs -i` as needed). Definitely **do not give sudo** power to the `ipfs` user, this defeats the purpose of having a separate user to isolate possible security issues in ipfs in the first place.

- All the rest seems fine!

[Next page](https://discuss.ipfs.tech/t/ipfs-cluster-how-to-please-review/5074.md?page=2)
