Nomploy Nomad Packs

← All packs

pwpush v0.1.0

Secrets

Password Pusher — securely share passwords and secret text via self-destructing links with expiry and view limits (an alternative to emailing secrets). Deployed as a single host-networked Nomad service with SQLite storage.

nomad-pack run pwpush --registry nomploy
…or one line (add registry + run)
curl -fsSL https://packs.nomploy.com/install.sh | sh -s -- pwpush

Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.

1 task http 5100 1 volume image pglombardo/pwpush:latest tracks :latest image bumped today
Variables 8
values.hcl

Save as values.hcl, edit, then run:

nomad-pack run pwpush -f values.hcl --registry nomploy
# The name of the Nomad job.
job_name = "pwpush"

# The Nomad namespace to deploy into.
namespace = "default"

# The datacenters to deploy to.
datacenters = ["*"]

# The Password Pusher container image. Pin a tag in production.
image = "pglombardo/pwpush:latest"

# Host port for the Password Pusher web UI.
port = 5100

# Named volume for the SQLite database and uploads (/opt/PasswordPusher/storage).
storage_volume = "pwpush_storage"

# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []

# Resources for the Password Pusher task.
resources = {
    cpu    = 400
    memory = 512
  }
NameTypeDefaultDescription
job_name string
"pwpush"
The name of the Nomad job.
namespace string
"default"
The Nomad namespace to deploy into.
datacenters list
["*"]
The datacenters to deploy to.
image string
"pglombardo/pwpush:latest"
The Password Pusher container image. Pin a tag in production.
port number
5100
Host port for the Password Pusher web UI.
storage_volume string
"pwpush_storage"
Named volume for the SQLite database and uploads (/opt/PasswordPusher/storage).
constraints list
[]
Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
resources object
{
    cpu    = 400
    memory = 512
  }
Resources for the Password Pusher task.
Back up this pack

This pack stores data in one Docker named volume: pwpush_storage

restic

# Run on the node hosting this pack. Point restic at your repo first:
#   export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>"
#   export RESTIC_PASSWORD="<repo-password>"
#   export AWS_ACCESS_KEY_ID=<key>  AWS_SECRET_ACCESS_KEY=<secret>
restic backup \
  /var/lib/docker/volumes/pwpush_storage/_data

rclone (sync to S3/R2)

rclone sync /var/lib/docker/volumes/pwpush_storage/_data backup:<bucket>/pwpush_storage

Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.

Readme

pwpush

Password Pusher lets you securely share passwords and secret text via self-destructing links — set an expiry (days / views) so secrets don't linger in chat or email. Also supports sharing files and URLs.

This pack runs Password Pusher as a single host-networked Nomad job with SQLite storage (in the pwpush_storage volume) — no external database is required.

Quick start

nomad-pack run pwpush --registry=nomploy

Then open http://<node-ip>:5100.

Configuration

Variable Default Notes
port 5100 Web UI host port
storage_volume pwpush_storage SQLite database + uploads

Since you're sending secrets through it, put Password Pusher behind HTTPS (a reverse proxy). For higher volume you can switch to PostgreSQL and S3-compatible storage via the DATABASE_URL / PWP__* environment variables (see the Password Pusher docs). Data persists in the pwpush_storage named volume.