# Automation

Source: https://docs.quake.ai/docs/automation
Markdown: https://docs.quake.ai/docs/automation.md
> Define Quake AI infrastructure as code with OpenTofu or Terraform for provisioning, and Ansible for configuration management and deployment.

---

# Automation

Define your Quake AI infrastructure in code, version it in git, and deploy it repeatably. **OpenTofu** is the recommended IaC tool for Quake AI: open source (MPL-2.0), fully compatible with Terraform providers and modules, and backed by the Linux Foundation. All Quake AI templates and documentation use OpenTofu. If your team uses Terraform, the same templates work without modification.

For the configuration-management layer above provisioning (installing software, deploying applications, hardening hosts), Quake AI documents **Ansible**. The recommended pattern is OpenTofu for Day 0 provisioning, Ansible for Day 1 and Day 2 configuration.

## What you can do

<UseCaseGrid>
<UseCaseCard
  title="Get started with Infrastructure as Code"
  description="Install OpenTofu, authenticate to Quake AI, and deploy your first infrastructure from code."
  href="/docs/automation/how-to/getting-started-iac"
  difficulty="beginner"
  estimatedTime="20 min"
  services={["Automation", "Compute", "Network"]}
/>
<UseCaseCard
  title="Deploy with OpenTofu"
  description="Provision instances, networks, and volumes using OpenTofu with the OpenStack provider."
  href="/docs/automation/how-to/terraform-simple"
  difficulty="intermediate"
  estimatedTime="15 min"
  services={["Automation", "Compute"]}
/>
<UseCaseCard
  title="Deploy a full stack"
  description="Build a multi-resource environment (networking, compute, storage, and security groups) in a single OpenTofu configuration."
  href="/docs/automation/how-to/terraform-full-stack"
  difficulty="intermediate"
  estimatedTime="30 min"
  services={["Automation", "Compute", "Network", "Storage"]}
/>
<UseCaseCard
  title="Configure hosts with Ansible"
  description="Install Ansible, authenticate to Quake AI, and run a playbook against an existing VM over SSH."
  href="/docs/automation/how-to/getting-started-ansible"
  difficulty="beginner"
  estimatedTime="20 min"
  services={["Automation", "Compute"]}
/>
<UseCaseCard
  title="Combine OpenTofu and Ansible"
  description="Provision a VM with OpenTofu, hand off to Ansible via dynamic inventory, and configure the host in a single workflow."
  href="/docs/automation/how-to/ansible-opentofu-workflow"
  difficulty="intermediate"
  estimatedTime="25 min"
  services={["Automation", "Compute", "Network"]}
/>
</UseCaseGrid>

## How it works

<Figure size="md" caption="OpenTofu workflow: HCL files drive plan and apply, the OpenStack provider creates Quake AI resources, and state is persisted to an S3 backend.">

```mermaid
---
config:
  theme: neutral
  flowchart:
    defaultRenderer: elk
    curve: basis
---
flowchart LR
  accTitle: OpenTofu workflow on Quake AI
  accDescr: HCL files are processed by tofu plan and tofu apply, which call the OpenStack provider to create resources, while state is persisted to a remote S3 backend.

  hcl["main.tf<br/>(HCL)"]
  plan["tofu plan"]
  apply["tofu apply"]
  provider["OpenStack provider"]
  state[("Remote state<br/>S3 backend")]

  subgraph rc["Quake AI resources"]
    direction TB
    inst["Instances"]
    net["Networks"]
    vol["Volumes"]
    sg["Security groups"]
  end

  hcl --> plan
  plan --> apply
  apply --> provider
  provider --> rc
  apply <--> state
```

</Figure>

OpenTofu and Terraform use the [OpenStack provider](https://registry.terraform.io/providers/terraform-provider-openstack/openstack/latest/docs) to manage Quake AI resources. You write `.tf` files declaring the desired state (instances, networks, volumes, security groups), and the tool calculates the diff, plans changes, and applies them. State lives locally or in a remote backend; Quake AI object storage works as an S3-compatible backend for remote state.

OpenTofu is the primary tool for Quake AI because it is fully open source, uses the same HCL language and provider ecosystem as Terraform, and supports state management, module reuse, and CI/CD integration. If your team already uses Terraform, every Quake AI template works with `terraform` in place of `tofu`.

## Get started

If you are new to Infrastructure as Code on Quake AI, start with the [getting started guide](/docs/automation/how-to/getting-started-iac). Once you have OpenTofu running, explore the [template library](/resources/iac-templates) for repeatable patterns or the [Simple VM example](/docs/automation/how-to/terraform-simple) for a focused walkthrough.

## Key concepts

<DocsSectionLinks section="automation/concepts" grouping="concepts" primaryOnly />

## Security considerations

IaC templates and state files can contain sensitive data: credentials, IP addresses, and resource IDs. Store OpenTofu state in encrypted remote backends, never commit `.tfstate` files to version control, and use OpenStack application credentials instead of user passwords in provider configuration. For platform-wide security practices, see [Security](/docs/security).

## Guides and reference

### How-to guides

<DocsSectionLinks section="automation/how-to" />

### Console guides

<ReferenceConsoleLinks service="automation" />

### Migration guides

<DocsSectionLinks section="automation/migration" />

### CLI reference

<ReferenceServiceLinks service="automation" group="cli" />

### API reference

<ReferenceServiceLinks service="automation" group="api" />

## Legacy: Heat orchestration

Quake AI supports [Heat](https://docs.openstack.org/heat/latest/) (OpenStack-native orchestration) for existing stacks. Heat is a legacy path; new projects should use OpenTofu. If you have Heat stacks in production, they continue to work. For details on Quake AI's OpenStack implementation, see [How Quake AI uses OpenStack](/resources/migration/openstack).

- [Create a Heat stack](/docs/automation/how-to/create-heat-stack)
- [Heat Simple Stack template](/resources/iac-templates/heat-simple-stack)

## Related services

Automation templates manage resources across the Quake AI services: [Compute](/docs/compute) instances, [Network](/docs/network) infrastructure, [Storage](/docs/platform#storage) volumes, and [Kubernetes](/docs/kubernetes) clusters. For storing OpenTofu state remotely, use [Object storage](/docs/object) with S3-compatible access.
