Nomploy Nomad Packs

← All packs

arcane v0.1.0

Device management

Arcane — a modern, easy-to-use Docker management UI (a Portainer alternative): containers, images, networks, volumes, Compose stacks and logs from the browser. Deployed as a single host-networked Nomad service that reads the host Docker socket, with SQLite storage.

nomad-pack run arcane --registry nomploy
…or one line (add registry + run)
curl -fsSL https://packs.nomploy.com/install.sh | sh -s -- arcane

Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.

1 task http 3552 1 volume image ghcr.io/getarcaneapp/arcane:latest tracks :latest image bumped today
Variables 12
values.hcl

Save as values.hcl, edit, then run:

nomad-pack run arcane -f values.hcl --registry nomploy
# The name of the Nomad job.
job_name = "arcane"

# The Nomad namespace to deploy into.
namespace = "default"

# The datacenters to deploy to.
datacenters = ["*"]

# The Arcane container image. Pin a tag in production.
image = "ghcr.io/getarcaneapp/arcane:latest"

# Host port for the Arcane web UI.
port = 3552

# Public URL of this Arcane instance (used for links and callbacks). Set to your domain in production.
app_url = "http://localhost:3552"

# 32-character key used to encrypt stored secrets. CHANGE THIS and keep it stable.
encryption_key = "change_me_32char_encryption_key!"

# Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable.
jwt_secret = "change_me_jwt_secret_to_a_long_random_value"

# Path to the host Docker socket Arcane manages.
docker_socket = "/var/run/docker.sock"

# Named volume for Arcane's SQLite database and state.
data_volume = "arcane_data"

# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []

# Resources for the Arcane task.
resources = {
    cpu    = 400
    memory = 512
  }
NameTypeDefaultDescription
job_name string
"arcane"
The name of the Nomad job.
namespace string
"default"
The Nomad namespace to deploy into.
datacenters list
["*"]
The datacenters to deploy to.
image string
"ghcr.io/getarcaneapp/arcane:latest"
The Arcane container image. Pin a tag in production.
port number
3552
Host port for the Arcane web UI.
app_url string
"http://localhost:3552"
Public URL of this Arcane instance (used for links and callbacks). Set to your domain in production.
encryption_key set me string
"change_me_32char_encryption_key!"
32-character key used to encrypt stored secrets. CHANGE THIS and keep it stable.
jwt_secret set me string
"change_me_jwt_secret_to_a_long_random_value"
Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable.
docker_socket string
"/var/run/docker.sock"
Path to the host Docker socket Arcane manages.
data_volume string
"arcane_data"
Named volume for Arcane's SQLite database and state.
constraints list
[]
Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
resources object
{
    cpu    = 400
    memory = 512
  }
Resources for the Arcane task.
Back up this pack

This pack stores data in one Docker named volume: arcane_data

restic

# Run on the node hosting this pack. Point restic at your repo first:
#   export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>"
#   export RESTIC_PASSWORD="<repo-password>"
#   export AWS_ACCESS_KEY_ID=<key>  AWS_SECRET_ACCESS_KEY=<secret>
restic backup \
  /var/lib/docker/volumes/arcane_data/_data

rclone (sync to S3/R2)

rclone sync /var/lib/docker/volumes/arcane_data/_data backup:<bucket>/arcane_data

Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.

Readme

arcane

Arcane is a modern, easy-to-use Docker management UI — a Portainer alternative. Manage containers, images, networks, volumes, Compose stacks and logs from the browser.

This pack runs Arcane as a single host-networked Nomad job. It reads the host's Docker socket to manage Docker, and stores its own state in SQLite inside the arcane_data volume — no external database is required.

Quick start

nomad-pack run arcane --registry=nomploy

Then open http://<node-ip>:3552 and create the first admin account.

Configuration

Variable Default Notes
port 3552 Web UI host port
app_url http://localhost:3552 Public URL — set to your domain in production
encryption_key change me Exactly 32 characters — encrypts stored secrets, keep stable
jwt_secret change me Session signing key — keep stable
docker_socket /var/run/docker.sock Host Docker socket to manage

Change encryption_key (exactly 32 chars) and jwt_secret before deploying anywhere real, and keep them stable.

Security

Arcane mounts the Docker socket, which is equivalent to root on the node. Keep it behind your VPN or an authenticating reverse proxy and restrict access. Data persists in the arcane_data named volume.