Nomploy Nomad Packs

← All packs

zoraxy v0.1.0

Networking

Zoraxy — a general-purpose HTTP reverse proxy and forwarding tool with a friendly web UI, TLS/ACME, virtual directories, access control and built-in network utilities. Deployed as a single host-networked Nomad service.

nomad-pack run zoraxy --registry nomploy
…or one line (add registry + run)
curl -fsSL https://packs.nomploy.com/install.sh | sh -s -- zoraxy

Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.

1 task admin 8000 2 volumes image zoraxydocker/zoraxy:latest tracks :latest image bumped today
Variables 9
values.hcl

Save as values.hcl, edit, then run:

nomad-pack run zoraxy -f values.hcl --registry nomploy
# The name of the Nomad job.
job_name = "zoraxy"

# The Nomad namespace to deploy into.
namespace = "default"

# The datacenters to deploy to.
datacenters = ["*"]

# The Zoraxy container image. Pin a tag in production.
image = "zoraxydocker/zoraxy:latest"

# Host port for the Zoraxy management web UI.
port = 8000

# Named volume for Zoraxy configuration and certificates (/opt/zoraxy/config).
config_volume = "zoraxy_config"

# Named volume for Zoraxy plugins (/opt/zoraxy/plugin).
plugin_volume = "zoraxy_plugin"

# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []

# The task resources.
resources = {
    cpu    = 500
    memory = 512
  }
NameTypeDefaultDescription
job_name string
"zoraxy"
The name of the Nomad job.
namespace string
"default"
The Nomad namespace to deploy into.
datacenters list
["*"]
The datacenters to deploy to.
image string
"zoraxydocker/zoraxy:latest"
The Zoraxy container image. Pin a tag in production.
port number
8000
Host port for the Zoraxy management web UI.
config_volume string
"zoraxy_config"
Named volume for Zoraxy configuration and certificates (/opt/zoraxy/config).
plugin_volume string
"zoraxy_plugin"
Named volume for Zoraxy plugins (/opt/zoraxy/plugin).
constraints list
[]
Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
resources object
{
    cpu    = 500
    memory = 512
  }
The task resources.
Back up this pack

This pack stores data in 2 Docker named volumes: zoraxy_configzoraxy_plugin

restic

# Run on the node hosting this pack. Point restic at your repo first:
#   export RESTIC_REPOSITORY="s3:https://<account>.r2.cloudflarestorage.com/<bucket>"
#   export RESTIC_PASSWORD="<repo-password>"
#   export AWS_ACCESS_KEY_ID=<key>  AWS_SECRET_ACCESS_KEY=<secret>
restic backup \
  /var/lib/docker/volumes/zoraxy_config/_data \
  /var/lib/docker/volumes/zoraxy_plugin/_data

rclone (sync to S3/R2)

rclone sync /var/lib/docker/volumes/zoraxy_config/_data backup:<bucket>/zoraxy_config
rclone sync /var/lib/docker/volumes/zoraxy_plugin/_data backup:<bucket>/zoraxy_plugin

Paths assume the default Docker volume location (/var/lib/docker/volumes). Restore by stopping the job, restoring files into the same volume, and re-running the pack.

Readme

zoraxy

Zoraxy is a general-purpose, self-hosted HTTP reverse proxy and forwarding tool with a genuinely friendly web UI. It handles virtual hosts and virtual directories, automatic TLS via ACME/Let's Encrypt, access control (geo-IP, whitelist/blacklist), redirects, a web SSH terminal, uptime monitoring and more — a lightweight alternative to Nginx Proxy Manager.

This pack runs Zoraxy as a single host-networked Nomad service. Host networking lets Zoraxy bind the ports it proxies (typically 80/443) on the node.

Deploy

nomad-pack run zoraxy --registry=nomploy

Open http://<node-ip>:8000 and create the admin account, then add your proxy hosts.

Configuration

Variable Default Description
image zoraxydocker/zoraxy:latest Container image (pin a tag in production).
port 8000 Host port for the management UI.
config_volume zoraxy_config Volume for config and certificates.
plugin_volume zoraxy_plugin Volume for plugins.
resources 500 MHz / 512 MB CPU and memory for the task.

Ports: Zoraxy binds the proxy ports (e.g. 80/443) itself at runtime via host networking. Deploy it on a node where those ports are free (not already taken by another ingress), and pin it there with constraints.

Configuration and certificates persist in config_volume.