Certimate — a self-hosted SSL/TLS certificate manager: request certificates from ACME CAs (Let's Encrypt, ZeroSSL, …), auto-renew them, and deploy them to your servers, CDNs and cloud services. Deployed as a single host-networked Nomad service with a data volume.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 9.3k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "certimate"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Certimate container image. Pin a tag in production.
image = "certimate/certimate:latest"
# Host port for the Certimate web UI.
port = 8090
# Named volume for Certimate's database and state (PocketBase pb_data).
data_volume = "certimate_data"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the Certimate task.
resources = {
cpu = 300
memory = 256
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "certimate" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "certimate/certimate:latest" | The Certimate container image. Pin a tag in production. |
| port | number | 8090 | Host port for the Certimate web UI. |
| data_volume | string | "certimate_data" | Named volume for Certimate's database and state (PocketBase pb_data). |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 300
memory = 256
} | Resources for the Certimate task. |
No variables match.
This pack stores data in one Docker named volume:
certimate_data
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/certimate_data/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/certimate_data/_data backup:<bucket>/certimate_data
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
Certimate is a self-hosted SSL/TLS certificate manager. Request certificates from ACME CAs (Let's Encrypt, ZeroSSL, Google, …) with DNS or HTTP challenges, auto-renew them, and deploy them to your servers, CDNs, load balancers and cloud services — all from one dashboard.
This pack runs Certimate as a single host-networked Nomad job. It's built on PocketBase
and stores everything (its database, certificates and provider credentials) in the
certimate_data volume — no external database is required.
nomad-pack run certimate --registry=nomploy
Then open http://<node-ip>:8090 and create the admin account.
| Variable | Default | Notes |
|---|---|---|
port |
8090 |
Web UI host port |
data_volume |
certimate_data |
Database + certificates + credentials |
Certimate stores API credentials for your DNS/hosting/cloud providers, so treat it as
sensitive: keep it behind your VPN or an authenticating reverse proxy, and back up the
certimate_data volume.