Nomploy Nomad Packs

← All packs

certimate v0.1.0

Secrets

Certimate — a self-hosted SSL/TLS certificate manager: request certificates from ACME CAs (Let's Encrypt, ZeroSSL, …), auto-renew them, and deploy them to your servers, CDNs and cloud services. Deployed as a single host-networked Nomad service with a data volume.

nomad-pack run certimate --registry nomploy
…or one line (add registry + run)
curl -fsSL https://packs.nomploy.com/install.sh | sh -s -- certimate

Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.

1 task http 8090 1 volume image certimate/certimate:latest tracks :latest image bumped today
Variables 8
values.hcl

Save as values.hcl, edit, then run:

nomad-pack run certimate -f values.hcl --registry nomploy
# The name of the Nomad job.
job_name = "certimate"

# The Nomad namespace to deploy into.
namespace = "default"

# The datacenters to deploy to.
datacenters = ["*"]

# The Certimate container image. Pin a tag in production.
image = "certimate/certimate:latest"

# Host port for the Certimate web UI.
port = 8090

# Named volume for Certimate's database and state (PocketBase pb_data).
data_volume = "certimate_data"

# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []

# Resources for the Certimate task.
resources = {
    cpu    = 300
    memory = 256
  }
NameTypeDefaultDescription
job_name string
"certimate"
The name of the Nomad job.
namespace string
"default"
The Nomad namespace to deploy into.
datacenters list
["*"]
The datacenters to deploy to.
image string
"certimate/certimate:latest"
The Certimate container image. Pin a tag in production.
port number
8090
Host port for the Certimate web UI.
data_volume string
"certimate_data"
Named volume for Certimate's database and state (PocketBase pb_data).
constraints list
[]
Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
resources object
{
    cpu    = 300
    memory = 256
  }
Resources for the Certimate task.
Back up this pack

This pack stores data in one Docker named volume: certimate_data

restic

# Run on the node hosting this pack. Point restic at your repo first:
#   export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>"
#   export RESTIC_PASSWORD="<repo-password>"
#   export AWS_ACCESS_KEY_ID=<key>  AWS_SECRET_ACCESS_KEY=<secret>
restic backup \
  /var/lib/docker/volumes/certimate_data/_data

rclone (sync to S3/R2)

rclone sync /var/lib/docker/volumes/certimate_data/_data backup:<bucket>/certimate_data

Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.

Readme

certimate

Certimate is a self-hosted SSL/TLS certificate manager. Request certificates from ACME CAs (Let's Encrypt, ZeroSSL, Google, …) with DNS or HTTP challenges, auto-renew them, and deploy them to your servers, CDNs, load balancers and cloud services — all from one dashboard.

This pack runs Certimate as a single host-networked Nomad job. It's built on PocketBase and stores everything (its database, certificates and provider credentials) in the certimate_data volume — no external database is required.

Quick start

nomad-pack run certimate --registry=nomploy

Then open http://<node-ip>:8090 and create the admin account.

Configuration

Variable Default Notes
port 8090 Web UI host port
data_volume certimate_data Database + certificates + credentials

Security

Certimate stores API credentials for your DNS/hosting/cloud providers, so treat it as sensitive: keep it behind your VPN or an authenticating reverse proxy, and back up the certimate_data volume.