ZITADEL — a modern identity and access management platform (OIDC, OAuth2, SAML, SCIM) with multi-tenancy, passwordless/MFA, and a management console (a Keycloak / Auth0 alternative). Deployed as an all-in-one host-networked Nomad job (PostgreSQL + app).
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 15.2k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "zitadel"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The ZITADEL container image. Pin a tag in production.
image = "ghcr.io/zitadel/zitadel:latest"
# The PostgreSQL image for the bundled database.
postgres_image = "postgres:16-alpine"
# Host port for the ZITADEL console / API.
port = 8080
# Host port for the bundled PostgreSQL.
db_port = 5432
# Password for the bundled PostgreSQL. CHANGE THIS.
db_password = "zitadel_change_me"
# Exactly 32-character key used to encrypt secrets at rest. CHANGE THIS and keep it stable.
masterkey = "ChangeMeToARandom32CharMasterKey"
# Public domain/host ZITADEL is reached at (no scheme). Must match how users access it.
external_domain = "localhost"
# Set true when served over HTTPS (e.g. behind Traefik); false for plain HTTP.
external_secure = "false"
# First-instance admin username (login is <username>@zitadel.<external_domain>).
admin_username = "zitadel-admin"
# First-instance admin password. CHANGE THIS (needs upper/lower/number/symbol, 8+).
admin_password = "Password1!"
# Named volume for PostgreSQL data.
db_data_volume = "zitadel_db_data"
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# Resources for the ZITADEL app task.
resources = {
cpu = 1000
memory = 1024
}
# Resources for the bundled PostgreSQL task.
db_resources = {
cpu = 500
memory = 512
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "zitadel" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "ghcr.io/zitadel/zitadel:latest" | The ZITADEL container image. Pin a tag in production. |
| postgres_image | string | "postgres:16-alpine" | The PostgreSQL image for the bundled database. |
| port | number | 8080 | Host port for the ZITADEL console / API. |
| db_port | number | 5432 | Host port for the bundled PostgreSQL. |
| db_password set me | string | "zitadel_change_me" | Password for the bundled PostgreSQL. CHANGE THIS. |
| masterkey set me | string | "ChangeMeToARandom32CharMasterKey" | Exactly 32-character key used to encrypt secrets at rest. CHANGE THIS and keep it stable. |
| external_domain | string | "localhost" | Public domain/host ZITADEL is reached at (no scheme). Must match how users access it. |
| external_secure | string | "false" | Set true when served over HTTPS (e.g. behind Traefik); false for plain HTTP. |
| admin_username | string | "zitadel-admin" | First-instance admin username (login is <username>@zitadel.<external_domain>). |
| admin_password key | string | "Password1!" | First-instance admin password. CHANGE THIS (needs upper/lower/number/symbol, 8+). |
| db_data_volume | string | "zitadel_db_data" | Named volume for PostgreSQL data. |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 1000
memory = 1024
} | Resources for the ZITADEL app task. |
| db_resources | object | {
cpu = 500
memory = 512
} | Resources for the bundled PostgreSQL task. |
No variables match.
This pack stores data in one Docker named volume:
zitadel_db_data
⚠ This pack bundles a database. A cold copy of the volume can be inconsistent — for a reliable backup, dump the DB (pg_dump / mysqldump) or stop the job while backing up.
restic
# Run on the node hosting this pack. Point restic at your repo first: # export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>" # export RESTIC_PASSWORD="<repo-password>" # export AWS_ACCESS_KEY_ID=<key> AWS_SECRET_ACCESS_KEY=<secret> restic backup \ /var/lib/docker/volumes/zitadel_db_data/_data
rclone (sync to S3/R2)
rclone sync /var/lib/docker/volumes/zitadel_db_data/_data backup:<bucket>/zitadel_db_data
Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.
ZITADEL is a modern, open-source identity and access management platform — a self-hosted alternative to Auth0 or Keycloak. It provides OIDC, OAuth2, SAML 2.0 and SCIM, multi-tenancy (organizations), passwordless and MFA, self-service and a polished management console, with an event-sourced audit trail.
This pack deploys ZITADEL all-in-one as a single host-networked Nomad job:
PostgreSQL (bundled as a prestart sidecar) plus the ZITADEL app. The database
is initialised and migrated automatically on first start (start-from-init).
nomad-pack run zitadel --registry=nomploy \
--var external_domain=auth.example.com --var external_secure=true \
--var masterkey=$(openssl rand -hex 16) \
--var db_password=$(openssl rand -hex 16) \
--var admin_password='S0me-Strong-Pass!'
Open http://<node-ip>:8080/ui/console and sign in as
zitadel-admin@zitadel.<external_domain>.
| Variable | Default | Description |
|---|---|---|
image |
ghcr.io/zitadel/zitadel:latest |
App image (pin a tag in production). |
postgres_image |
postgres:16-alpine |
Bundled PostgreSQL image. |
port |
8080 |
Host port for the console / API. |
db_password |
zitadel_change_me |
PostgreSQL password — change this. |
masterkey |
placeholder (32 chars) | Secrets-encryption key — change & keep stable. |
external_domain |
localhost |
Public host ZITADEL is reached at. |
external_secure |
false |
true when served over HTTPS. |
admin_username |
zitadel-admin |
First admin (login <user>@zitadel.<domain>). |
admin_password |
Password1! |
First admin password — change this. |
resources |
1000 MHz / 1024 MB | App task resources. |
Important:
external_domain/external_secureare baked into issued tokens and OIDC discovery — set them to the real public address up front; changing them later breaks existing clients.masterkeymust be exactly 32 characters and stay constant. PostgreSQL data persists indb_data_volume.