Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (postgresql-latest, 2026-09-14), podman (1.19, 2026-09-14); Proxmox VM: docker (postgresql-latest, 2026-09-14), podman (1.19, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
umami:
image: "ghcr.io/umami-software/umami:postgresql-latest"
container_name: njorddeploy-umami
restart: unless-stopped
user: "0:0"
ports:
- "3000:3000"
environment:
- "DATABASE_URL=postgresql://umami:umami_secure_db_pass@njorddeploy-umami-db:5432/umami"
- "APP_SECRET=random_umami_secret_salt_32_chars_min"
depends_on:
njorddeploy-umami-db:
condition: service_healthy
networks:
- njorddeploy_net
njorddeploy-umami-db:
image: postgres:15-alpine
container_name: njorddeploy-umami-db
restart: unless-stopped
user: "0:0"
environment:
- "POSTGRES_DB=umami"
- "POSTGRES_USER=umami"
- "POSTGRES_PASSWORD=umami_secure_db_pass"
volumes:
- "./data/umami/db:/var/lib/postgresql/data"
healthcheck:
test: ["CMD-SHELL", "pg_isready -U umami -d umami"]
interval: 5s
timeout: 5s
retries: 5
networks:
- njorddeploy_net
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
UMAMI_WEB_PORT |
3000 |
The external port for accessing the Umami web interface. |
POSTGRES_DB |
umami |
The database name for Umami. |
POSTGRES_USER |
umami |
The database user for Umami. |
POSTGRES_PASSWORD |
umami_secure_db_pass |
The database password for the Umami database user. |
UMAMI_APP_SECRET |
random_umami_secret_salt_32_chars_min |
A random salt string used by Umami for session encryption. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.