Nomploy Nomad Packs

← All packs

infisical v0.1.0

Secrets

Infisical — an open-source secrets management platform for storing, syncing and rotating application secrets across your team and infra (a Vault / Doppler alternative). Deployed as an all-in-one host-networked Nomad job (PostgreSQL + Redis + app).

nomad-pack run infisical --registry nomploy
…or one line (add registry + run)
curl -fsSL https://packs.nomploy.com/install.sh | sh -s -- infisical

Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.

3 tasks http 8080db 5432redis 6379 2 volumes image infisical/infisical:latest tracks :latest image bumped today
Variables 19
values.hcl

Save as values.hcl, edit, then run:

nomad-pack run infisical -f values.hcl --registry nomploy
# The name of the Nomad job.
job_name = "infisical"

# The Nomad namespace to deploy into.
namespace = "default"

# The datacenters to deploy to.
datacenters = ["*"]

# The Infisical container image. Pin a tag in production.
image = "infisical/infisical:latest"

# The PostgreSQL image for the bundled database.
postgres_image = "postgres:14-alpine"

# The Redis image for the bundled cache.
redis_image = "redis:7-alpine"

# Host port for the Infisical web UI / API.
port = 8080

# Host port for the bundled PostgreSQL.
db_port = 5432

# Host port for the bundled Redis.
redis_port = 6379

# Password for the bundled PostgreSQL. CHANGE THIS.
db_password = "infisical_change_me"

# 16-byte (32 hex chars) key for encrypting secrets at rest (openssl rand -hex 16). CHANGE THIS.
encryption_key = "00000000000000000000000000000000"

# Base64 32-byte secret for signing auth tokens (openssl rand -base64 32). CHANGE THIS.
auth_secret = "aGVsbG9fY2hhbmdlX21lX3RvX2FfcmFuZG9tX3ZhbHVlXzAwMDA="

# Public URL of this Infisical instance (used in links/emails).
site_url = "http://localhost:8080"

# Named volume for PostgreSQL data.
db_data_volume = "infisical_db_data"

# Named volume for Redis data.
redis_data_volume = "infisical_redis_data"

# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []

# Resources for the Infisical app task.
resources = {
    cpu    = 1000
    memory = 1024
  }

# Resources for the bundled PostgreSQL task.
db_resources = {
    cpu    = 500
    memory = 512
  }

# Resources for the bundled Redis task.
redis_resources = {
    cpu    = 200
    memory = 128
  }
NameTypeDefaultDescription
job_name string
"infisical"
The name of the Nomad job.
namespace string
"default"
The Nomad namespace to deploy into.
datacenters list
["*"]
The datacenters to deploy to.
image string
"infisical/infisical:latest"
The Infisical container image. Pin a tag in production.
postgres_image string
"postgres:14-alpine"
The PostgreSQL image for the bundled database.
redis_image string
"redis:7-alpine"
The Redis image for the bundled cache.
port number
8080
Host port for the Infisical web UI / API.
db_port number
5432
Host port for the bundled PostgreSQL.
redis_port number
6379
Host port for the bundled Redis.
db_password set me string
"infisical_change_me"
Password for the bundled PostgreSQL. CHANGE THIS.
encryption_key key string
"00000000000000000000000000000000"
16-byte (32 hex chars) key for encrypting secrets at rest (openssl rand -hex 16). CHANGE THIS.
auth_secret key string
"aGVsbG9fY2hhbmdlX21lX3RvX2FfcmFuZG9tX3ZhbHVlXzAwMDA="
Base64 32-byte secret for signing auth tokens (openssl rand -base64 32). CHANGE THIS.
site_url string
"http://localhost:8080"
Public URL of this Infisical instance (used in links/emails).
db_data_volume string
"infisical_db_data"
Named volume for PostgreSQL data.
redis_data_volume string
"infisical_redis_data"
Named volume for Redis data.
constraints list
[]
Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
resources object
{
    cpu    = 1000
    memory = 1024
  }
Resources for the Infisical app task.
db_resources object
{
    cpu    = 500
    memory = 512
  }
Resources for the bundled PostgreSQL task.
redis_resources object
{
    cpu    = 200
    memory = 128
  }
Resources for the bundled Redis task.
Back up this pack

This pack stores data in 2 Docker named volumes: infisical_db_datainfisical_redis_data

⚠ This pack bundles a database. A cold copy of the volume can be inconsistent — for a reliable backup, dump the DB (pg_dump / mysqldump) or stop the job while backing up.

restic

# Run on the node hosting this pack. Point restic at your repo first:
#   export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>"
#   export RESTIC_PASSWORD="<repo-password>"
#   export AWS_ACCESS_KEY_ID=<key>  AWS_SECRET_ACCESS_KEY=<secret>
restic backup \
  /var/lib/docker/volumes/infisical_db_data/_data \
  /var/lib/docker/volumes/infisical_redis_data/_data

rclone (sync to S3/R2)

rclone sync /var/lib/docker/volumes/infisical_db_data/_data backup:<bucket>/infisical_db_data
rclone sync /var/lib/docker/volumes/infisical_redis_data/_data backup:<bucket>/infisical_redis_data

Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.

Readme

infisical

Infisical is an open-source secrets management platform — a self-hosted alternative to HashiCorp Vault, Doppler or AWS Secrets Manager. Teams use it to store, organise and sync application secrets and configs across environments, with secret versioning and rotation, point-in-time recovery, dynamic secrets, a web UI, CLI, SDKs and Kubernetes/CI integrations.

This pack deploys Infisical all-in-one as a single host-networked Nomad job: PostgreSQL and Redis (bundled as prestart sidecars) plus the Infisical app. Database migrations run automatically on start.

Deploy

nomad-pack run infisical --registry=nomploy \
  --var db_password=$(openssl rand -hex 16) \
  --var encryption_key=$(openssl rand -hex 16) \
  --var auth_secret=$(openssl rand -base64 32) \
  --var site_url=https://secrets.example.com

Open http://<node-ip>:8080 and create the first admin account.

Configuration

Variable Default Description
image infisical/infisical:latest App image (pin a tag in production).
postgres_image postgres:14-alpine Bundled PostgreSQL image.
redis_image redis:7-alpine Bundled Redis image.
port 8080 Host port for the web UI / API.
db_password infisical_change_me PostgreSQL password — change this.
encryption_key placeholder (32 hex) Secrets encryption key — change & keep stable.
auth_secret placeholder (base64) Auth-token secret — change & keep stable.
site_url http://localhost:8080 Public URL of the instance.
resources 1000 MHz / 1024 MB App task resources.

Important: encryption_key and auth_secret must remain constant for the life of the deployment — changing them makes previously stored secrets unreadable.

Data persists in separate volumes for PostgreSQL and Redis.