Documenso — the open-source DocuSign alternative for signing documents. Deployed as an all-in-one host-networked Nomad job (PostgreSQL + a self-signed signing certificate + the app). Uploads are stored in the database by default; set SMTP to send signing emails.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 15.3k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "documenso"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Documenso container image. Pin a tag in production.
image = "documenso/documenso:latest"
# The PostgreSQL image for the bundled database.
postgres_image = "postgres:16"
# Image used by the init task to generate the self-signed signing certificate.
openssl_image = "alpine/openssl:latest"
# Host port for the Documenso web UI.
port = 3000
# Host port for the bundled PostgreSQL (loopback only).
db_port = 5432
# Public URL of this Documenso instance (used for links and callbacks).
webapp_url = "http://localhost:3000"
# Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable.
nextauth_secret = "change_me_nextauth_secret_to_a_long_random_value"
# Primary encryption key for stored secrets (openssl rand -base64 32). CHANGE THIS and keep it stable.
encryption_key = "change_me_encryption_key_to_a_long_random_value"
# Secondary encryption key (openssl rand -base64 32). CHANGE THIS and keep it stable.
encryption_secondary_key = "change_me_secondary_key_to_a_long_random_value"
# Password for the bundled PostgreSQL. CHANGE THIS.
db_password = "documenso_change_me"
# Email transport: smtp-auth, smtp-api, resend, or mailchannels. The app boots without a working mailer, but signing emails will fail until this is configured.
smtp_transport = "smtp-auth"
# SMTP server host (for smtp-auth). Leave blank to configure later.
smtp_host = ""
# SMTP server port (for smtp-auth).
smtp_port = "587"
# SMTP username (for smtp-auth).
smtp_username = ""
# SMTP password (for smtp-auth).
smtp_password = ""
# Display name for outgoing email.
smtp_from_name = "Documenso"
# From address for outgoing email.
smtp_from_address = "noreply@example.com"
# Named volume for PostgreSQL data.
db_data_volume = "documenso_db_data"
# Named volume holding the generated signing certificate.
cert_volume = "documenso_cert"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the Documenso app task.
resources = {
cpu = 1000
memory = 1024
}
# Resources for the bundled PostgreSQL task.
db_resources = {
cpu = 500
memory = 512
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "documenso" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "documenso/documenso:latest" | The Documenso container image. Pin a tag in production. |
| postgres_image | string | "postgres:16" | The PostgreSQL image for the bundled database. |
| openssl_image | string | "alpine/openssl:latest" | Image used by the init task to generate the self-signed signing certificate. |
| port | number | 3000 | Host port for the Documenso web UI. |
| db_port | number | 5432 | Host port for the bundled PostgreSQL (loopback only). |
| webapp_url | string | "http://localhost:3000" | Public URL of this Documenso instance (used for links and callbacks). |
| nextauth_secret set me | string | "change_me_nextauth_secret_to_a_long_random_value" | Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable. |
| encryption_key set me | string | "change_me_encryption_key_to_a_long_random_value" | Primary encryption key for stored secrets (openssl rand -base64 32). CHANGE THIS and keep it stable. |
| encryption_secondary_key set me | string | "change_me_secondary_key_to_a_long_random_value" | Secondary encryption key (openssl rand -base64 32). CHANGE THIS and keep it stable. |
| db_password set me | string | "documenso_change_me" | Password for the bundled PostgreSQL. CHANGE THIS. |
| smtp_transport | string | "smtp-auth" | Email transport: smtp-auth, smtp-api, resend, or mailchannels. The app boots without a working mailer, but signing emails will fail until this is configured. |
| smtp_host | string | "" | SMTP server host (for smtp-auth). Leave blank to configure later. |
| smtp_port | string | "587" | SMTP server port (for smtp-auth). |
| smtp_username | string | "" | SMTP username (for smtp-auth). |
| smtp_password key | string | "" | SMTP password (for smtp-auth). |
| smtp_from_name | string | "Documenso" | Display name for outgoing email. |
| smtp_from_address set me | string | "noreply@example.com" | From address for outgoing email. |
| db_data_volume | string | "documenso_db_data" | Named volume for PostgreSQL data. |
| cert_volume | string | "documenso_cert" | Named volume holding the generated signing certificate. |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 1000
memory = 1024
} | Resources for the Documenso app task. |
| db_resources | object | {
cpu = 500
memory = 512
} | Resources for the bundled PostgreSQL task. |
No variables match.
This pack stores data in 2 Docker named volumes:
documenso_certdocumenso_db_data
⚠ This pack bundles a database. A cold copy of the volume can be inconsistent — for a reliable backup, dump the DB (pg_dump / mysqldump) or stop the job while backing up.
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/documenso_cert/_data \ /var/lib/docker/volumes/documenso_db_data/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/documenso_cert/_data backup:<bucket>/documenso_cert rclone sync /var/lib/docker/volumes/documenso_db_data/_data backup:<bucket>/documenso_db_data
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
Documenso is the open-source DocuSign alternative — send, sign and manage documents with a signing workflow you host yourself.
This pack runs Documenso all-in-one as a single host-networked Nomad job:
documenso/documenso:latest)documenso_cert volume if one isn't there yetAll tasks share the host network and talk over 127.0.0.1, so no mesh networking is
required. Uploads are stored in the database by default (NEXT_PUBLIC_UPLOAD_TRANSPORT= database), so no S3 bucket is needed. Database migrations run automatically on first
start.
nomad-pack run documenso --registry=nomploy
Then open http://<node-ip>:3000 and create the first account.
| Variable | Default | Notes |
|---|---|---|
port |
3000 |
Web UI host port |
webapp_url |
http://localhost:3000 |
Public URL — set before real use |
nextauth_secret |
change me | Session signing secret — keep stable |
encryption_key |
change me | Primary encryption key — keep stable |
encryption_secondary_key |
change me | Secondary encryption key — keep stable |
db_password |
change me | Bundled PostgreSQL password |
smtp_transport |
smtp-auth |
smtp-auth, smtp-api, resend, mailchannels |
smtp_host / smtp_username / smtp_password |
(blank) | Set to send signing emails |
smtp_from_address |
noreply@example.com |
From address for outgoing mail |
Change every secret before deploying anywhere real, and keep nextauth_secret,
encryption_key and encryption_secondary_key stable across deploys.
The app boots without a working mailer, but it can't send signing invitations until SMTP
is configured. Set smtp_host, smtp_username and smtp_password (with transport
smtp-auth), or switch smtp_transport to resend / mailchannels and supply their
keys.
The signing certificate generated by cert-init is self-signed. Signed PDFs will
show an untrusted-issuer warning in some readers. For legally recognized signatures,
replace cert.p12 in the documenso_cert volume with a certificate from a trusted CA
(and set NEXT_PRIVATE_SIGNING_PASSPHRASE if it is protected).
Data persists in the documenso_db_data and documenso_cert named volumes.