Nomploy Nomad Packs

← All packs

documenso v0.1.0

Productivity

Documenso — the open-source DocuSign alternative for signing documents. Deployed as an all-in-one host-networked Nomad job (PostgreSQL + a self-signed signing certificate + the app). Uploads are stored in the database by default; set SMTP to send signing emails.

nomad-pack run documenso --registry nomploy
…or one line (add registry + run)
curl -fsSL https://packs.nomploy.com/install.sh | sh -s -- documenso

Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.

3 tasks http 3000db 5432 2 volumes image documenso/documenso:latest tracks :latest image bumped today
Variables 25
values.hcl

Save as values.hcl, edit, then run:

nomad-pack run documenso -f values.hcl --registry nomploy
# The name of the Nomad job.
job_name = "documenso"

# The Nomad namespace to deploy into.
namespace = "default"

# The datacenters to deploy to.
datacenters = ["*"]

# The Documenso container image. Pin a tag in production.
image = "documenso/documenso:latest"

# The PostgreSQL image for the bundled database.
postgres_image = "postgres:16"

# Image used by the init task to generate the self-signed signing certificate.
openssl_image = "alpine/openssl:latest"

# Host port for the Documenso web UI.
port = 3000

# Host port for the bundled PostgreSQL (loopback only).
db_port = 5432

# Public URL of this Documenso instance (used for links and callbacks).
webapp_url = "http://localhost:3000"

# Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable.
nextauth_secret = "change_me_nextauth_secret_to_a_long_random_value"

# Primary encryption key for stored secrets (openssl rand -base64 32). CHANGE THIS and keep it stable.
encryption_key = "change_me_encryption_key_to_a_long_random_value"

# Secondary encryption key (openssl rand -base64 32). CHANGE THIS and keep it stable.
encryption_secondary_key = "change_me_secondary_key_to_a_long_random_value"

# Password for the bundled PostgreSQL. CHANGE THIS.
db_password = "documenso_change_me"

# Email transport: smtp-auth, smtp-api, resend, or mailchannels. The app boots without a working mailer, but signing emails will fail until this is configured.
smtp_transport = "smtp-auth"

# SMTP server host (for smtp-auth). Leave blank to configure later.
smtp_host = ""

# SMTP server port (for smtp-auth).
smtp_port = "587"

# SMTP username (for smtp-auth).
smtp_username = ""

# SMTP password (for smtp-auth).
smtp_password = ""

# Display name for outgoing email.
smtp_from_name = "Documenso"

# From address for outgoing email.
smtp_from_address = "noreply@example.com"

# Named volume for PostgreSQL data.
db_data_volume = "documenso_db_data"

# Named volume holding the generated signing certificate.
cert_volume = "documenso_cert"

# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []

# Resources for the Documenso app task.
resources = {
    cpu    = 1000
    memory = 1024
  }

# Resources for the bundled PostgreSQL task.
db_resources = {
    cpu    = 500
    memory = 512
  }
NameTypeDefaultDescription
job_name string
"documenso"
The name of the Nomad job.
namespace string
"default"
The Nomad namespace to deploy into.
datacenters list
["*"]
The datacenters to deploy to.
image string
"documenso/documenso:latest"
The Documenso container image. Pin a tag in production.
postgres_image string
"postgres:16"
The PostgreSQL image for the bundled database.
openssl_image string
"alpine/openssl:latest"
Image used by the init task to generate the self-signed signing certificate.
port number
3000
Host port for the Documenso web UI.
db_port number
5432
Host port for the bundled PostgreSQL (loopback only).
webapp_url string
"http://localhost:3000"
Public URL of this Documenso instance (used for links and callbacks).
nextauth_secret set me string
"change_me_nextauth_secret_to_a_long_random_value"
Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable.
encryption_key set me string
"change_me_encryption_key_to_a_long_random_value"
Primary encryption key for stored secrets (openssl rand -base64 32). CHANGE THIS and keep it stable.
encryption_secondary_key set me string
"change_me_secondary_key_to_a_long_random_value"
Secondary encryption key (openssl rand -base64 32). CHANGE THIS and keep it stable.
db_password set me string
"documenso_change_me"
Password for the bundled PostgreSQL. CHANGE THIS.
smtp_transport string
"smtp-auth"
Email transport: smtp-auth, smtp-api, resend, or mailchannels. The app boots without a working mailer, but signing emails will fail until this is configured.
smtp_host string
""
SMTP server host (for smtp-auth). Leave blank to configure later.
smtp_port string
"587"
SMTP server port (for smtp-auth).
smtp_username string
""
SMTP username (for smtp-auth).
smtp_password key string
""
SMTP password (for smtp-auth).
smtp_from_name string
"Documenso"
Display name for outgoing email.
smtp_from_address set me string
"noreply@example.com"
From address for outgoing email.
db_data_volume string
"documenso_db_data"
Named volume for PostgreSQL data.
cert_volume string
"documenso_cert"
Named volume holding the generated signing certificate.
constraints list
[]
Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
resources object
{
    cpu    = 1000
    memory = 1024
  }
Resources for the Documenso app task.
db_resources object
{
    cpu    = 500
    memory = 512
  }
Resources for the bundled PostgreSQL task.
Back up this pack

This pack stores data in 2 Docker named volumes: documenso_certdocumenso_db_data

⚠ This pack bundles a database. A cold copy of the volume can be inconsistent — for a reliable backup, dump the DB (pg_dump / mysqldump) or stop the job while backing up.

restic

# Run on the node hosting this pack. Point restic at your repo first:
#   export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>"
#   export RESTIC_PASSWORD="<repo-password>"
#   export AWS_ACCESS_KEY_ID=<key>  AWS_SECRET_ACCESS_KEY=<secret>
restic backup \
  /var/lib/docker/volumes/documenso_cert/_data \
  /var/lib/docker/volumes/documenso_db_data/_data

rclone (sync to S3/R2)

rclone sync /var/lib/docker/volumes/documenso_cert/_data backup:<bucket>/documenso_cert
rclone sync /var/lib/docker/volumes/documenso_db_data/_data backup:<bucket>/documenso_db_data

Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.

Readme

documenso

Documenso is the open-source DocuSign alternative — send, sign and manage documents with a signing workflow you host yourself.

This pack runs Documenso all-in-one as a single host-networked Nomad job:

All tasks share the host network and talk over 127.0.0.1, so no mesh networking is required. Uploads are stored in the database by default (NEXT_PUBLIC_UPLOAD_TRANSPORT= database), so no S3 bucket is needed. Database migrations run automatically on first start.

Quick start

nomad-pack run documenso --registry=nomploy

Then open http://<node-ip>:3000 and create the first account.

Configuration

Variable Default Notes
port 3000 Web UI host port
webapp_url http://localhost:3000 Public URL — set before real use
nextauth_secret change me Session signing secret — keep stable
encryption_key change me Primary encryption key — keep stable
encryption_secondary_key change me Secondary encryption key — keep stable
db_password change me Bundled PostgreSQL password
smtp_transport smtp-auth smtp-auth, smtp-api, resend, mailchannels
smtp_host / smtp_username / smtp_password (blank) Set to send signing emails
smtp_from_address noreply@example.com From address for outgoing mail

Change every secret before deploying anywhere real, and keep nextauth_secret, encryption_key and encryption_secondary_key stable across deploys.

Email and signing

The app boots without a working mailer, but it can't send signing invitations until SMTP is configured. Set smtp_host, smtp_username and smtp_password (with transport smtp-auth), or switch smtp_transport to resend / mailchannels and supply their keys.

The signing certificate generated by cert-init is self-signed. Signed PDFs will show an untrusted-issuer warning in some readers. For legally recognized signatures, replace cert.p12 in the documenso_cert volume with a certificate from a trusted CA (and set NEXT_PRIVATE_SIGNING_PASSPHRASE if it is protected).

Data persists in the documenso_db_data and documenso_cert named volumes.