Nomploy Nomad Packs

← All packs

zitadel v0.1.0

Identity

ZITADEL — a modern identity and access management platform (OIDC, OAuth2, SAML, SCIM) with multi-tenancy, passwordless/MFA, and a management console (a Keycloak / Auth0 alternative). Deployed as an all-in-one host-networked Nomad job (PostgreSQL + app).

nomad-pack run zitadel --registry nomploy
…or one line (add registry + run)
curl -fsSL https://packs.nomploy.com/install.sh | sh -s -- zitadel

Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.

2 tasks http 8080db 5432 1 volume image ghcr.io/zitadel/zitadel:latest tracks :latest image bumped today
Variables 17
values.hcl

Save as values.hcl, edit, then run:

nomad-pack run zitadel -f values.hcl --registry nomploy
# The name of the Nomad job.
job_name = "zitadel"

# The Nomad namespace to deploy into.
namespace = "default"

# The datacenters to deploy to.
datacenters = ["*"]

# The ZITADEL container image. Pin a tag in production.
image = "ghcr.io/zitadel/zitadel:latest"

# The PostgreSQL image for the bundled database.
postgres_image = "postgres:16-alpine"

# Host port for the ZITADEL console / API.
port = 8080

# Host port for the bundled PostgreSQL.
db_port = 5432

# Password for the bundled PostgreSQL. CHANGE THIS.
db_password = "zitadel_change_me"

# Exactly 32-character key used to encrypt secrets at rest. CHANGE THIS and keep it stable.
masterkey = "ChangeMeToARandom32CharMasterKey"

# Public domain/host ZITADEL is reached at (no scheme). Must match how users access it.
external_domain = "localhost"

# Set true when served over HTTPS (e.g. behind Traefik); false for plain HTTP.
external_secure = "false"

# First-instance admin username (login is <username>@zitadel.<external_domain>).
admin_username = "zitadel-admin"

# First-instance admin password. CHANGE THIS (needs upper/lower/number/symbol, 8+).
admin_password = "Password1!"

# Named volume for PostgreSQL data.
db_data_volume = "zitadel_db_data"

# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []

# Resources for the ZITADEL app task.
resources = {
    cpu    = 1000
    memory = 1024
  }

# Resources for the bundled PostgreSQL task.
db_resources = {
    cpu    = 500
    memory = 512
  }
NameTypeDefaultDescription
job_name string
"zitadel"
The name of the Nomad job.
namespace string
"default"
The Nomad namespace to deploy into.
datacenters list
["*"]
The datacenters to deploy to.
image string
"ghcr.io/zitadel/zitadel:latest"
The ZITADEL container image. Pin a tag in production.
postgres_image string
"postgres:16-alpine"
The PostgreSQL image for the bundled database.
port number
8080
Host port for the ZITADEL console / API.
db_port number
5432
Host port for the bundled PostgreSQL.
db_password set me string
"zitadel_change_me"
Password for the bundled PostgreSQL. CHANGE THIS.
masterkey set me string
"ChangeMeToARandom32CharMasterKey"
Exactly 32-character key used to encrypt secrets at rest. CHANGE THIS and keep it stable.
external_domain string
"localhost"
Public domain/host ZITADEL is reached at (no scheme). Must match how users access it.
external_secure string
"false"
Set true when served over HTTPS (e.g. behind Traefik); false for plain HTTP.
admin_username string
"zitadel-admin"
First-instance admin username (login is <username>@zitadel.<external_domain>).
admin_password key string
"Password1!"
First-instance admin password. CHANGE THIS (needs upper/lower/number/symbol, 8+).
db_data_volume string
"zitadel_db_data"
Named volume for PostgreSQL data.
constraints list
[]
Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
resources object
{
    cpu    = 1000
    memory = 1024
  }
Resources for the ZITADEL app task.
db_resources object
{
    cpu    = 500
    memory = 512
  }
Resources for the bundled PostgreSQL task.
Back up this pack

This pack stores data in one Docker named volume: zitadel_db_data

⚠ This pack bundles a database. A cold copy of the volume can be inconsistent — for a reliable backup, dump the DB (pg_dump / mysqldump) or stop the job while backing up.

restic

# Run on the node hosting this pack. Point restic at your repo first:
#   export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>"
#   export RESTIC_PASSWORD="<repo-password>"
#   export AWS_ACCESS_KEY_ID=<key>  AWS_SECRET_ACCESS_KEY=<secret>
restic backup \
  /var/lib/docker/volumes/zitadel_db_data/_data

rclone (sync to S3/R2)

rclone sync /var/lib/docker/volumes/zitadel_db_data/_data backup:<bucket>/zitadel_db_data

Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.

Readme

zitadel

ZITADEL is a modern, open-source identity and access management platform — a self-hosted alternative to Auth0 or Keycloak. It provides OIDC, OAuth2, SAML 2.0 and SCIM, multi-tenancy (organizations), passwordless and MFA, self-service and a polished management console, with an event-sourced audit trail.

This pack deploys ZITADEL all-in-one as a single host-networked Nomad job: PostgreSQL (bundled as a prestart sidecar) plus the ZITADEL app. The database is initialised and migrated automatically on first start (start-from-init).

Deploy

nomad-pack run zitadel --registry=nomploy \
  --var external_domain=auth.example.com --var external_secure=true \
  --var masterkey=$(openssl rand -hex 16) \
  --var db_password=$(openssl rand -hex 16) \
  --var admin_password='S0me-Strong-Pass!'

Open http://<node-ip>:8080/ui/console and sign in as zitadel-admin@zitadel.<external_domain>.

Configuration

Variable Default Description
image ghcr.io/zitadel/zitadel:latest App image (pin a tag in production).
postgres_image postgres:16-alpine Bundled PostgreSQL image.
port 8080 Host port for the console / API.
db_password zitadel_change_me PostgreSQL password — change this.
masterkey placeholder (32 chars) Secrets-encryption key — change & keep stable.
external_domain localhost Public host ZITADEL is reached at.
external_secure false true when served over HTTPS.
admin_username zitadel-admin First admin (login <user>@zitadel.<domain>).
admin_password Password1! First admin password — change this.
resources 1000 MHz / 1024 MB App task resources.

Important: external_domain/external_secure are baked into issued tokens and OIDC discovery — set them to the real public address up front; changing them later breaks existing clients. masterkey must be exactly 32 characters and stay constant. PostgreSQL data persists in db_data_volume.