Kaneo — an open-source project management platform: boards, tasks, time tracking and team collaboration, kept simple. Deployed as an all-in-one host-networked Nomad job (PostgreSQL + the Kaneo app, which serves both the API and the web UI).
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 9.3k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "kaneo"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Kaneo container image (serves both the API and the web UI). Pin a tag in production.
image = "ghcr.io/usekaneo/kaneo:latest"
# The PostgreSQL image for the bundled database.
postgres_image = "postgres:16-alpine"
# Host port for the Kaneo web UI / API.
port = 5173
# Host port for the bundled PostgreSQL (loopback only).
db_port = 5432
# Password for the bundled PostgreSQL. CHANGE THIS.
db_password = "kaneo_change_me"
# Secret used to sign auth sessions (openssl rand -hex 32). CHANGE THIS and keep it stable.
auth_secret = "0000000000000000000000000000000000000000000000000000000000000000"
# Public URL of this Kaneo instance (used to build API/client links). Set to your domain in production.
client_url = "http://localhost:5173"
# Named volume for PostgreSQL data.
db_data_volume = "kaneo_db_data"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the Kaneo app task.
resources = {
cpu = 500
memory = 512
}
# Resources for the bundled PostgreSQL task.
db_resources = {
cpu = 500
memory = 512
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "kaneo" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "ghcr.io/usekaneo/kaneo:latest" | The Kaneo container image (serves both the API and the web UI). Pin a tag in production. |
| postgres_image | string | "postgres:16-alpine" | The PostgreSQL image for the bundled database. |
| port | number | 5173 | Host port for the Kaneo web UI / API. |
| db_port | number | 5432 | Host port for the bundled PostgreSQL (loopback only). |
| db_password set me | string | "kaneo_change_me" | Password for the bundled PostgreSQL. CHANGE THIS. |
| auth_secret key | string | "0000000000000000000000000000000000000000000000000000000000000000" | Secret used to sign auth sessions (openssl rand -hex 32). CHANGE THIS and keep it stable. |
| client_url | string | "http://localhost:5173" | Public URL of this Kaneo instance (used to build API/client links). Set to your domain in production. |
| db_data_volume | string | "kaneo_db_data" | Named volume for PostgreSQL data. |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 500
memory = 512
} | Resources for the Kaneo app task. |
| db_resources | object | {
cpu = 500
memory = 512
} | Resources for the bundled PostgreSQL task. |
No variables match.
This pack stores data in one Docker named volume:
kaneo_db_data
⚠ This pack bundles a database. A cold copy of the volume can be inconsistent — for a reliable backup, dump the DB (pg_dump / mysqldump) or stop the job while backing up.
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/kaneo_db_data/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/kaneo_db_data/_data backup:<bucket>/kaneo_db_data
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
Kaneo is an open-source project management platform — boards, tasks, time tracking and team collaboration, kept deliberately simple.
This pack runs Kaneo all-in-one as a single host-networked Nomad job:
ghcr.io/usekaneo/kaneo:latest)Both share the host network and talk over 127.0.0.1, so no mesh networking is required.
Database migrations run automatically on first start.
nomad-pack run kaneo --registry=nomploy
Then open http://<node-ip>:5173 and create the first account.
| Variable | Default | Notes |
|---|---|---|
port |
5173 |
Web UI / API host port |
client_url |
http://localhost:5173 |
Public URL — set to your domain in production |
db_password |
change me | Bundled PostgreSQL password |
auth_secret |
0000… |
Session signing key (openssl rand -hex 32) — keep stable |
Change db_password and auth_secret before deploying anywhere real, and keep
auth_secret stable across deploys (rotating it signs everyone out). The app derives its
database connection from the POSTGRES_* settings, so no separate DATABASE_URL is
needed.
Data persists in the kaneo_db_data named volume.