Infisical — an open-source secrets management platform for storing, syncing and rotating application secrets across your team and infra (a Vault / Doppler alternative). Deployed as an all-in-one host-networked Nomad job (PostgreSQL + Redis + app).
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 29.5k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "infisical"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Infisical container image. Pin a tag in production.
image = "infisical/infisical:latest"
# The PostgreSQL image for the bundled database.
postgres_image = "postgres:14-alpine"
# The Redis image for the bundled cache.
redis_image = "redis:7-alpine"
# Host port for the Infisical web UI / API.
port = 8080
# Host port for the bundled PostgreSQL.
db_port = 5432
# Host port for the bundled Redis.
redis_port = 6379
# Password for the bundled PostgreSQL. CHANGE THIS.
db_password = "infisical_change_me"
# 16-byte (32 hex chars) key for encrypting secrets at rest (openssl rand -hex 16). CHANGE THIS.
encryption_key = "00000000000000000000000000000000"
# Base64 32-byte secret for signing auth tokens (openssl rand -base64 32). CHANGE THIS.
auth_secret = "aGVsbG9fY2hhbmdlX21lX3RvX2FfcmFuZG9tX3ZhbHVlXzAwMDA="
# Public URL of this Infisical instance (used in links/emails).
site_url = "http://localhost:8080"
# Named volume for PostgreSQL data.
db_data_volume = "infisical_db_data"
# Named volume for Redis data.
redis_data_volume = "infisical_redis_data"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the Infisical app task.
resources = {
cpu = 1000
memory = 1024
}
# Resources for the bundled PostgreSQL task.
db_resources = {
cpu = 500
memory = 512
}
# Resources for the bundled Redis task.
redis_resources = {
cpu = 200
memory = 128
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "infisical" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "infisical/infisical:latest" | The Infisical container image. Pin a tag in production. |
| postgres_image | string | "postgres:14-alpine" | The PostgreSQL image for the bundled database. |
| redis_image | string | "redis:7-alpine" | The Redis image for the bundled cache. |
| port | number | 8080 | Host port for the Infisical web UI / API. |
| db_port | number | 5432 | Host port for the bundled PostgreSQL. |
| redis_port | number | 6379 | Host port for the bundled Redis. |
| db_password set me | string | "infisical_change_me" | Password for the bundled PostgreSQL. CHANGE THIS. |
| encryption_key key | string | "00000000000000000000000000000000" | 16-byte (32 hex chars) key for encrypting secrets at rest (openssl rand -hex 16). CHANGE THIS. |
| auth_secret key | string | "aGVsbG9fY2hhbmdlX21lX3RvX2FfcmFuZG9tX3ZhbHVlXzAwMDA=" | Base64 32-byte secret for signing auth tokens (openssl rand -base64 32). CHANGE THIS. |
| site_url | string | "http://localhost:8080" | Public URL of this Infisical instance (used in links/emails). |
| db_data_volume | string | "infisical_db_data" | Named volume for PostgreSQL data. |
| redis_data_volume | string | "infisical_redis_data" | Named volume for Redis data. |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 1000
memory = 1024
} | Resources for the Infisical app task. |
| db_resources | object | {
cpu = 500
memory = 512
} | Resources for the bundled PostgreSQL task. |
| redis_resources | object | {
cpu = 200
memory = 128
} | Resources for the bundled Redis task. |
No variables match.
This pack stores data in 2 Docker named volumes:
infisical_db_datainfisical_redis_data
⚠ This pack bundles a database. A cold copy of the volume can be inconsistent — for a reliable backup, dump the DB (pg_dump / mysqldump) or stop the job while backing up.
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/infisical_db_data/_data \ /var/lib/docker/volumes/infisical_redis_data/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/infisical_db_data/_data backup:<bucket>/infisical_db_data rclone sync /var/lib/docker/volumes/infisical_redis_data/_data backup:<bucket>/infisical_redis_data
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
Infisical is an open-source secrets management platform — a self-hosted alternative to HashiCorp Vault, Doppler or AWS Secrets Manager. Teams use it to store, organise and sync application secrets and configs across environments, with secret versioning and rotation, point-in-time recovery, dynamic secrets, a web UI, CLI, SDKs and Kubernetes/CI integrations.
This pack deploys Infisical all-in-one as a single host-networked Nomad job: PostgreSQL and Redis (bundled as prestart sidecars) plus the Infisical app. Database migrations run automatically on start.
nomad-pack run infisical --registry=nomploy \
--var db_password=$(openssl rand -hex 16) \
--var encryption_key=$(openssl rand -hex 16) \
--var auth_secret=$(openssl rand -base64 32) \
--var site_url=https://secrets.example.com
Open http://<node-ip>:8080 and create the first admin account.
| Variable | Default | Description |
|---|---|---|
image |
infisical/infisical:latest |
App image (pin a tag in production). |
postgres_image |
postgres:14-alpine |
Bundled PostgreSQL image. |
redis_image |
redis:7-alpine |
Bundled Redis image. |
port |
8080 |
Host port for the web UI / API. |
db_password |
infisical_change_me |
PostgreSQL password — change this. |
encryption_key |
placeholder (32 hex) | Secrets encryption key — change & keep stable. |
auth_secret |
placeholder (base64) | Auth-token secret — change & keep stable. |
site_url |
http://localhost:8080 |
Public URL of the instance. |
resources |
1000 MHz / 1024 MB | App task resources. |
Important:
encryption_keyandauth_secretmust remain constant for the life of the deployment — changing them makes previously stored secrets unreadable.
Data persists in separate volumes for PostgreSQL and Redis.