MeshCentral — a self-hosted remote monitoring and management server for controlling computers over the web (a TeamViewer / remote-desktop alternative) with remote desktop, terminal and file transfer. Deployed as a single host-networked Nomad service.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 7.3k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "meshcentral"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The MeshCentral container image. Pin a tag in production.
image = "ghcr.io/ylianst/meshcentral:latest"
# Host port for the MeshCentral web UI (HTTPS).
port = 4430
# Host port for the HTTP-to-HTTPS redirect.
redir_port = 8081
# Public hostname/IP of this server (used in agent config). Set to your node's address.
hostname = "localhost"
# Allow self-registration of new accounts after the first admin (true/false).
allow_new_accounts = "false"
# Named volume for MeshCentral config and its embedded database (/opt/meshcentral/meshcentral-data).
data_volume = "meshcentral_data"
# Named volume for user files (/opt/meshcentral/meshcentral-files).
files_volume = "meshcentral_files"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# The task resources.
resources = {
cpu = 500
memory = 512
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "meshcentral" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "ghcr.io/ylianst/meshcentral:latest" | The MeshCentral container image. Pin a tag in production. |
| port | number | 4430 | Host port for the MeshCentral web UI (HTTPS). |
| redir_port | number | 8081 | Host port for the HTTP-to-HTTPS redirect. |
| hostname | string | "localhost" | Public hostname/IP of this server (used in agent config). Set to your node's address. |
| allow_new_accounts | string | "false" | Allow self-registration of new accounts after the first admin (true/false). |
| data_volume | string | "meshcentral_data" | Named volume for MeshCentral config and its embedded database (/opt/meshcentral/meshcentral-data). |
| files_volume | string | "meshcentral_files" | Named volume for user files (/opt/meshcentral/meshcentral-files). |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 500
memory = 512
} | The task resources. |
No variables match.
This pack stores data in 2 Docker named volumes:
meshcentral_datameshcentral_files
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/meshcentral_data/_data \ /var/lib/docker/volumes/meshcentral_files/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/meshcentral_data/_data backup:<bucket>/meshcentral_data rclone sync /var/lib/docker/volumes/meshcentral_files/_data backup:<bucket>/meshcentral_files
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
MeshCentral is a full, self-hosted remote monitoring and management (RMM) server — a self-hosted alternative to TeamViewer/AnyDesk and commercial RMMs. From a web browser you get remote desktop, terminal and file transfer, wake-on-LAN, device grouping, two-factor auth and more, across Windows, macOS and Linux agents.
This pack runs MeshCentral as a single host-networked Nomad service using its built-in database (NeDB) — no external MongoDB required.
nomad-pack run meshcentral --registry=nomploy --var hostname=mesh.example.com
Open https://<node-ip>:4430 (self-signed certificate) and create the first
account, which becomes the administrator.
| Variable | Default | Description |
|---|---|---|
image |
ghcr.io/ylianst/meshcentral:latest |
Container image (pin a tag in production). |
port |
4430 |
Host port for the HTTPS web UI. |
redir_port |
8081 |
HTTP→HTTPS redirect port. |
hostname |
localhost |
Public hostname/IP used in agent config. |
allow_new_accounts |
false |
Allow self-registration after the first user. |
data_volume |
meshcentral_data |
Volume for config + embedded DB. |
files_volume |
meshcentral_files |
Volume for user files. |
resources |
500 MHz / 512 MB | CPU and memory for the task. |
The HTTPS port defaults to 4430 (not the privileged 443) to avoid clashing
with an ingress proxy. Set hostname to the address agents should connect to.
Config and the NeDB database persist in data_volume.