A node joins with a join token and a manager's address. One token makes the new node a worker, the other a manager; docker swarm join-token worker (or manager) prints either again, and --rotate replaces a leaked one. The token also encodes the cluster CA's fingerprint, so the joining node can verify the swarm before trusting it. Join swarm-2 and swarm-3 as workers:
T=$(m1 swarm join-token -q worker)
for i in 2 3; do docker exec l3-swarm-$i docker swarm join --token $T $IP1:2377; done
m1 node ls --format '{{.ID}} {{.Hostname}} {{.Status}} {{.ManagerStatus}}'
docker exec l3-swarm-2 docker node ls 2>&1 | cut -c 1-90This node joined a swarm as a worker. This node joined a swarm as a worker. 4xhthladtlt05mfw796tiskb8 swarm-1 Ready Leader vuz8w7n0o7sp9jm9b4y66kq55 swarm-2 Ready 57holi3ewowbqnbspfu57s12p swarm-3 Ready Error response from daemon: This node is not a swarm manager. Worker nodes can't be used t
The asterisk marks the node you are talking to; a worker has no copy of the cluster state and refuses. Managers keep the Raft log consistent by majority vote, so a swarm with one manager survives no manager failure, three managers survive one and five survive two; an even number adds nothing (four also survive only one). docker node promote swarm-2 turns a worker into a manager and demote reverses it. If the managers lose quorum, running tasks keep serving, but nothing can be scheduled, updated or joined until quorum returns or docker swarm init --force-new-cluster is run on a surviving manager. One manager, as here, suits a lab only.