Password Pusher — securely share passwords and secret text via self-destructing links with expiry and view limits (an alternative to emailing secrets). Deployed as a single host-networked Nomad service with SQLite storage.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 3.2k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "pwpush"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The Password Pusher container image. Pin a tag in production.
image = "pglombardo/pwpush:latest"
# Host port for the Password Pusher web UI.
port = 5100
# Named volume for the SQLite database and uploads (/opt/PasswordPusher/storage).
storage_volume = "pwpush_storage"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the Password Pusher task.
resources = {
cpu = 400
memory = 512
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "pwpush" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "pglombardo/pwpush:latest" | The Password Pusher container image. Pin a tag in production. |
| port | number | 5100 | Host port for the Password Pusher web UI. |
| storage_volume | string | "pwpush_storage" | Named volume for the SQLite database and uploads (/opt/PasswordPusher/storage). |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 400
memory = 512
} | Resources for the Password Pusher task. |
No variables match.
This pack stores data in one Docker named volume:
pwpush_storage
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/pwpush_storage/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/pwpush_storage/_data backup:<bucket>/pwpush_storage
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
Password Pusher lets you securely share passwords and secret text via self-destructing links — set an expiry (days / views) so secrets don't linger in chat or email. Also supports sharing files and URLs.
This pack runs Password Pusher as a single host-networked Nomad job with SQLite storage
(in the pwpush_storage volume) — no external database is required.
nomad-pack run pwpush --registry=nomploy
Then open http://<node-ip>:5100.
| Variable | Default | Notes |
|---|---|---|
port |
5100 |
Web UI host port |
storage_volume |
pwpush_storage |
SQLite database + uploads |
Since you're sending secrets through it, put Password Pusher behind HTTPS (a reverse
proxy). For higher volume you can switch to PostgreSQL and S3-compatible storage via the
DATABASE_URL / PWP__* environment variables (see the Password Pusher docs). Data
persists in the pwpush_storage named volume.