Langfuse — open-source LLM engineering platform: tracing, evals, prompt management, and metrics for AI apps (an alternative to LangSmith). Deployed as an all-in-one host-networked Nomad job (PostgreSQL + ClickHouse + Redis + MinIO + web + worker). Needs a node with ~8 GB free RAM.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 35.3k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "langfuse"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Langfuse web image.
image = "docker.langfuse.com/langfuse/langfuse:4"
# The Langfuse worker image. Keep its tag in sync with the web image.
worker_image = "docker.langfuse.com/langfuse/langfuse-worker:4"
# The PostgreSQL image for the bundled database.
postgres_image = "postgres:17"
# The ClickHouse image for the bundled OLAP store.
clickhouse_image = "clickhouse/clickhouse-server:25.12"
# The Redis image for the bundled cache/queue.
redis_image = "redis:7"
# The MinIO image for the bundled S3-compatible blob store. Uses the publicly pullable Chainguard build (the minio/minio Docker Hub image now requires authentication).
minio_image = "cgr.dev/chainguard/minio:latest"
# Host port for the Langfuse web UI / API.
port = 3000
# Host port for the Langfuse worker (loopback only).
worker_port = 3030
# Host port for the bundled PostgreSQL (loopback only).
db_port = 5432
# Host port for the bundled ClickHouse HTTP interface (loopback only).
clickhouse_http_port = 8123
# Host port for the bundled ClickHouse native protocol (loopback only).
clickhouse_native_port = 9000
# Host port for the bundled Redis (loopback only).
redis_port = 6379
# Host port for the bundled MinIO S3 API (loopback only).
minio_port = 9100
# Host port for the bundled MinIO web console (loopback only).
minio_console_port = 9101
# Public URL of this Langfuse instance (used for auth callbacks and links).
nextauth_url = "http://localhost:3000"
# Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable.
nextauth_secret = "change_me_nextauth_secret_to_a_long_random_value"
# Salt for hashing API keys (openssl rand -base64 32). CHANGE THIS and keep it stable.
salt = "change_me_salt_to_a_long_random_value"
# 32-byte key as 64 hex chars (openssl rand -hex 32), encrypts stored secrets. CHANGE THIS and keep it stable.
encryption_key = "0000000000000000000000000000000000000000000000000000000000000000"
# Password for the bundled PostgreSQL. CHANGE THIS.
db_password = "langfuse_change_me"
# Password for the bundled ClickHouse. CHANGE THIS.
clickhouse_password = "clickhouse_change_me"
# Password (requirepass) for the bundled Redis. CHANGE THIS.
redis_password = "redis_change_me"
# Root password for the bundled MinIO. CHANGE THIS.
minio_root_password = "minio_change_me"
# Browser-reachable URL of the bundled MinIO S3 API, used to sign media URLs. Set to a public URL (e.g. https://s3.example.com) when exposing media; defaults to the loopback API port.
s3_public_endpoint = "http://localhost:9100"
# Whether Langfuse sends anonymous usage telemetry to the project.
telemetry_enabled = "true"
# Named volume for PostgreSQL data.
db_data_volume = "langfuse_db_data"
# Named volume for ClickHouse data.
clickhouse_data_volume = "langfuse_clickhouse_data"
# Named volume for MinIO blob data.
minio_data_volume = "langfuse_minio_data"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the Langfuse web task.
resources = {
cpu = 1000
memory = 1536
}
# Resources for the Langfuse worker task.
worker_resources = {
cpu = 1000
memory = 1536
}
# Resources for the bundled PostgreSQL task.
db_resources = {
cpu = 500
memory = 512
}
# Resources for the bundled ClickHouse task.
clickhouse_resources = {
cpu = 1000
memory = 3072
}
# Resources for the bundled Redis task.
redis_resources = {
cpu = 200
memory = 256
}
# Resources for the bundled MinIO task.
minio_resources = {
cpu = 300
memory = 512
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "langfuse" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "docker.langfuse.com/langfuse/langfuse:4" | The Langfuse web image. |
| worker_image | string | "docker.langfuse.com/langfuse/langfuse-worker:4" | The Langfuse worker image. Keep its tag in sync with the web image. |
| postgres_image | string | "postgres:17" | The PostgreSQL image for the bundled database. |
| clickhouse_image | string | "clickhouse/clickhouse-server:25.12" | The ClickHouse image for the bundled OLAP store. |
| redis_image | string | "redis:7" | The Redis image for the bundled cache/queue. |
| minio_image | string | "cgr.dev/chainguard/minio:latest" | The MinIO image for the bundled S3-compatible blob store. Uses the publicly pullable Chainguard build (the minio/minio Docker Hub image now requires authentication). |
| port | number | 3000 | Host port for the Langfuse web UI / API. |
| worker_port | number | 3030 | Host port for the Langfuse worker (loopback only). |
| db_port | number | 5432 | Host port for the bundled PostgreSQL (loopback only). |
| clickhouse_http_port | number | 8123 | Host port for the bundled ClickHouse HTTP interface (loopback only). |
| clickhouse_native_port | number | 9000 | Host port for the bundled ClickHouse native protocol (loopback only). |
| redis_port | number | 6379 | Host port for the bundled Redis (loopback only). |
| minio_port | number | 9100 | Host port for the bundled MinIO S3 API (loopback only). |
| minio_console_port | number | 9101 | Host port for the bundled MinIO web console (loopback only). |
| nextauth_url | string | "http://localhost:3000" | Public URL of this Langfuse instance (used for auth callbacks and links). |
| nextauth_secret set me | string | "change_me_nextauth_secret_to_a_long_random_value" | Secret used to sign auth sessions (openssl rand -base64 32). CHANGE THIS and keep it stable. |
| salt set me | string | "change_me_salt_to_a_long_random_value" | Salt for hashing API keys (openssl rand -base64 32). CHANGE THIS and keep it stable. |
| encryption_key key | string | "0000000000000000000000000000000000000000000000000000000000000000" | 32-byte key as 64 hex chars (openssl rand -hex 32), encrypts stored secrets. CHANGE THIS and keep it stable. |
| db_password set me | string | "langfuse_change_me" | Password for the bundled PostgreSQL. CHANGE THIS. |
| clickhouse_password set me | string | "clickhouse_change_me" | Password for the bundled ClickHouse. CHANGE THIS. |
| redis_password set me | string | "redis_change_me" | Password (requirepass) for the bundled Redis. CHANGE THIS. |
| minio_root_password set me | string | "minio_change_me" | Root password for the bundled MinIO. CHANGE THIS. |
| s3_public_endpoint | string | "http://localhost:9100" | Browser-reachable URL of the bundled MinIO S3 API, used to sign media URLs. Set to a public URL (e.g. https://s3.example.com) when exposing media; defaults to the loopback API port. |
| telemetry_enabled | string | "true" | Whether Langfuse sends anonymous usage telemetry to the project. |
| db_data_volume | string | "langfuse_db_data" | Named volume for PostgreSQL data. |
| clickhouse_data_volume | string | "langfuse_clickhouse_data" | Named volume for ClickHouse data. |
| minio_data_volume | string | "langfuse_minio_data" | Named volume for MinIO blob data. |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 1000
memory = 1536
} | Resources for the Langfuse web task. |
| worker_resources | object | {
cpu = 1000
memory = 1536
} | Resources for the Langfuse worker task. |
| db_resources | object | {
cpu = 500
memory = 512
} | Resources for the bundled PostgreSQL task. |
| clickhouse_resources | object | {
cpu = 1000
memory = 3072
} | Resources for the bundled ClickHouse task. |
| redis_resources | object | {
cpu = 200
memory = 256
} | Resources for the bundled Redis task. |
| minio_resources | object | {
cpu = 300
memory = 512
} | Resources for the bundled MinIO task. |
No variables match.
This pack stores data in 3 Docker named volumes:
langfuse_db_datalangfuse_clickhouse_datalangfuse_minio_data
⚠ This pack bundles a database. A cold copy of the volume can be inconsistent — for a reliable backup, dump the DB (pg_dump / mysqldump) or stop the job while backing up.
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/langfuse_db_data/_data \ /var/lib/docker/volumes/langfuse_clickhouse_data/_data \ /var/lib/docker/volumes/langfuse_minio_data/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/langfuse_db_data/_data backup:<bucket>/langfuse_db_data rclone sync /var/lib/docker/volumes/langfuse_clickhouse_data/_data backup:<bucket>/langfuse_clickhouse_data rclone sync /var/lib/docker/volumes/langfuse_minio_data/_data backup:<bucket>/langfuse_minio_data
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
Langfuse is an open-source LLM engineering platform — tracing, evaluations, prompt management, datasets and metrics for AI applications (an open alternative to LangSmith).
This pack runs Langfuse all-in-one as a single host-networked Nomad job:
docker.langfuse.com/langfuse/langfuse:4)docker.langfuse.com/langfuse/langfuse-worker:4)All tasks share the host network and talk to each other over 127.0.0.1, so no mesh
networking is required. Database and ClickHouse migrations run automatically on first
start.
This is a heavy stack (six containers). Schedule it on a node with ~8 GB free RAM.
On a nomploy cluster, pin it to the control plane with a constraint on
${meta.nomploy_control_plane} (see constraints).
nomad-pack run langfuse --registry=nomploy
Then open http://<node-ip>:3000 and create the first user and organization.
| Variable | Default | Notes |
|---|---|---|
port |
3000 |
Web UI / API host port |
nextauth_url |
http://localhost:3000 |
Public URL (auth callbacks, links) |
nextauth_secret |
change me | Session signing secret — keep stable |
salt |
change me | API-key hashing salt — keep stable |
encryption_key |
0000… |
64 hex chars (openssl rand -hex 32) — keep stable |
db_password |
change me | Bundled PostgreSQL password |
clickhouse_password |
change me | Bundled ClickHouse password |
redis_password |
change me | Bundled Redis password |
minio_root_password |
change me | Bundled MinIO root/secret password |
s3_public_endpoint |
http://localhost:9100 |
Browser-reachable MinIO URL for media links |
Change every secret before deploying anywhere real, and keep nextauth_secret,
salt and encryption_key stable across deploys (rotating encryption_key makes
previously stored secrets unreadable).
Data persists in the langfuse_db_data, langfuse_clickhouse_data and
langfuse_minio_data named volumes.