Arcane — a modern, easy-to-use Docker management UI (a Portainer alternative): containers, images, networks, volumes, Compose stacks and logs from the browser. Deployed as a single host-networked Nomad service that reads the host Docker socket, with SQLite storage.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 7.7k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "arcane"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Arcane container image. Pin a tag in production.
image = "ghcr.io/getarcaneapp/arcane:latest"
# Host port for the Arcane web UI.
port = 3552
# Public URL of this Arcane instance (used for links and callbacks). Set to your domain in production.
app_url = "http://localhost:3552"
# 32-character key used to encrypt stored secrets. CHANGE THIS and keep it stable.
encryption_key = "change_me_32char_encryption_key!"
# Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable.
jwt_secret = "change_me_jwt_secret_to_a_long_random_value"
# Path to the host Docker socket Arcane manages.
docker_socket = "/var/run/docker.sock"
# Named volume for Arcane's SQLite database and state.
data_volume = "arcane_data"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the Arcane task.
resources = {
cpu = 400
memory = 512
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "arcane" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "ghcr.io/getarcaneapp/arcane:latest" | The Arcane container image. Pin a tag in production. |
| port | number | 3552 | Host port for the Arcane web UI. |
| app_url | string | "http://localhost:3552" | Public URL of this Arcane instance (used for links and callbacks). Set to your domain in production. |
| encryption_key set me | string | "change_me_32char_encryption_key!" | 32-character key used to encrypt stored secrets. CHANGE THIS and keep it stable. |
| jwt_secret set me | string | "change_me_jwt_secret_to_a_long_random_value" | Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable. |
| docker_socket | string | "/var/run/docker.sock" | Path to the host Docker socket Arcane manages. |
| data_volume | string | "arcane_data" | Named volume for Arcane's SQLite database and state. |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 400
memory = 512
} | Resources for the Arcane task. |
No variables match.
This pack stores data in one Docker named volume:
arcane_data
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/arcane_data/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/arcane_data/_data backup:<bucket>/arcane_data
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
Arcane is a modern, easy-to-use Docker management UI — a Portainer alternative. Manage containers, images, networks, volumes, Compose stacks and logs from the browser.
This pack runs Arcane as a single host-networked Nomad job. It reads the host's Docker
socket to manage Docker, and stores its own state in SQLite inside the arcane_data
volume — no external database is required.
nomad-pack run arcane --registry=nomploy
Then open http://<node-ip>:3552 and create the first admin account.
| Variable | Default | Notes |
|---|---|---|
port |
3552 |
Web UI host port |
app_url |
http://localhost:3552 |
Public URL — set to your domain in production |
encryption_key |
change me | Exactly 32 characters — encrypts stored secrets, keep stable |
jwt_secret |
change me | Session signing key — keep stable |
docker_socket |
/var/run/docker.sock |
Host Docker socket to manage |
Change encryption_key (exactly 32 chars) and jwt_secret before deploying anywhere real,
and keep them stable.
Arcane mounts the Docker socket, which is equivalent to root on the node. Keep it behind
your VPN or an authenticating reverse proxy and restrict access. Data persists in the
arcane_data named volume.