cubeshipd/umami
Umami
Umami is a simple, privacy-focused web analytics tool — an open-source alternative to Google Analytics that stores no cookies and keeps your visitors' data on your own server.
Umami on Cubeship
Umami is a simple, privacy-focused web analytics tool — an open-source alternative to Google Analytics that stores no cookies and keeps your visitors' data on your own server.
This template installs it on a Cubeship instance with the managed Postgres it needs.
What it creates
- web — the Umami dashboard and tracking endpoint, from
ghcr.io/umami-software/umami:3.3.1, answering on the domain you choose. - umami-db — a managed Postgres 18 database, attached to the app, so
DATABASE_URLis set for you.
What you are asked
| Input | What to give |
|---|---|
| Where the dashboard answers | A domain you control, pointed at your instance. |
| The app's session secret | Nothing — the instance generates it and shows it once. |
After installing
- Open the domain and sign in with
admin/umami. - Change that password straight away under Settings → Profile.
- Add a website and paste the tracking snippet into your site.
Two-factor authentication
Umami only offers it with TWO_FACTOR_ENCRYPTION_KEY set to 64 hex
characters, which this template cannot generate. To turn it on, add the
variable to the web app yourself and redeploy:
openssl rand -hex 32
Resources
The app is limited to 1 CPU and 1 GiB of memory. Raise limits in
template.yaml if your traffic needs more.
What this creates
web
ghcr.io/umami-software/umami:3.3.1
umami-db
Postgres 18
# yaml-language-server: $schema=https://cubeship.dev/schema/template/v1.json
version: 1
name: 'Umami'
minCubeship: "0.6.0"
project: umami
inputs:
- key: domain
type: domain
label: Where the dashboard answers
- key: appSecret
type: secret
label: The app's session secret
generate: 32
databases:
- key: db
name: umami-db
engine: postgres
version: "18"
database: umami
apps:
- key: web
name: web
image: ghcr.io/umami-software/umami
# Umami 3 runs on Postgres only, so there is no DATABASE_TYPE to set.
tag: "3.3.1"
port: 3000
health: /api/heartbeat
domains:
- host: ${input.domain}
attach:
- database: db
limits: { cpu: 1, memory: 1Gi }
env:
APP_SECRET: ${input.appSecret}