# Cloud Automation and Orchestration

Source: https://docs.quake.ai/docs/automation/concepts/cloud-automation
Markdown: https://docs.quake.ai/docs/automation/concepts/cloud-automation.md

---

# Cloud automation and orchestration

Cloud automation replaces manual, click-through provisioning with code that describes your infrastructure. Instead of logging into a dashboard to create a VM, a network, and a security group one at a time, you write a configuration file that declares all three and their relationships. A tool reads that file and creates everything in the correct order, every time.

This approach is called **Infrastructure as Code (IaC)**, and it is the foundation of repeatable, auditable cloud operations.

## Why infrastructure as code matters

Manual provisioning works for a single server. It breaks down when you need to reproduce an environment, hand it to a teammate, roll back a change, or run the same stack in staging and production. IaC solves these problems:

- **Repeatability.** The same configuration file produces the same infrastructure. No undocumented dashboard clicks.
- **Version control.** Infrastructure definitions live in Git alongside application code. You can review changes in a pull request, revert a bad deploy, and trace who changed what.
- **Collaboration.** A shared configuration file is a single source of truth. Team members work from the same definition rather than a wiki page with screenshots.
- **Automation.** CI/CD pipelines can provision and tear down environments without human intervention.

## IaC on Quake AI

Quake AI supports three IaC tools for provisioning, plus Ansible for configuration management above the provisioning layer. **OpenTofu is the default** for Day 0 provisioning on new projects; Quake AI templates and how-to guides use OpenTofu. **Ansible handles Day 1 and Day 2** host configuration after OpenTofu provisions the infrastructure.

The split is sometimes called Day 0 / Day 1 / Day 2:

- **Day 0** (provision): create VMs, networks, security groups, floating IPs. OpenTofu owns this layer.
- **Day 1** (configure): install packages, harden SSH, deploy your application onto a freshly provisioned host. Ansible owns this layer.
- **Day 2** (operate): patch hosts, rotate credentials, run drift correction. Ansible runs against the existing inventory.

### OpenTofu (default for provisioning)

[OpenTofu](https://opentofu.org/) is an open-source infrastructure tool hosted by the Linux Foundation. It uses HCL (HashiCorp Configuration Language) to declare resources and manages state in a local or remote state file.

On Quake AI, OpenTofu uses the OpenStack provider to manage compute instances, networks, security groups, block storage, and floating IPs. For S3-compatible object storage, it uses the AWS provider with a custom endpoint.

Key strengths for Quake AI users:

- **Plan before apply.** `tofu plan` shows exactly what will change before any resource is created, modified, or destroyed.
- **Multi-provider support.** Manage Quake AI resources and external services (DNS, monitoring, S3 storage) in a single configuration.
- **Module ecosystem.** Reuse community modules from the Terraform Registry. OpenTofu is fully compatible with Terraform providers and modules.
- **Open-source license.** MPL-2.0 with no usage restrictions.

### Terraform (supported)

Terraform and OpenTofu share the same HCL syntax, provider ecosystem, and state format. Quake AI OpenTofu templates run with `terraform` instead of `tofu` without modification. If your team already has Terraform workflows, they work on Quake AI as-is.

### Heat (legacy)

OpenStack Heat is the built-in orchestration service on Quake AI. It uses HOT (Heat Orchestration Template) YAML files and manages state server-side. Heat can only orchestrate OpenStack-native resources; it cannot manage external services, and it has no equivalent of `plan` or a module registry.

Heat remains supported for existing stacks. New projects and templates use OpenTofu.

### Ansible (configuration management above OpenTofu)

[Ansible](https://www.ansible.com/) is an agentless configuration-management tool from Red Hat. It runs YAML playbooks against an inventory of hosts to install packages, edit files, manage services, and deploy applications. Ansible does not replace OpenTofu; it sits one layer above it. OpenTofu provisions the VM, then Ansible logs in over SSH and configures it.

The `openstack.cloud` Ansible collection can also drive Quake AI's API directly, for cases where a small amount of provisioning lives alongside configuration. The combined pattern is documented in [How to use Ansible with OpenTofu on Quake AI](/docs/automation/how-to/ansible-opentofu-workflow).

For a deeper walkthrough of when to reach for Ansible, read [Ansible on Quake AI](/docs/automation/concepts/ansible).

## Choosing the right tool

| Situation | Recommendation |
|---|---|
| New project, no existing IaC | OpenTofu for Day 0 provisioning, Ansible for Day 1 configuration |
| Existing Terraform workflows | Keep Terraform for provisioning; add Ansible for configuration |
| Existing Heat stacks in production | Keep Heat for those stacks; use OpenTofu for new resources |
| Multi-cloud (Quake AI + AWS/GCP) | OpenTofu or Terraform; Ansible runs against any of them |
| Need to install software, deploy apps, or harden OS on existing VMs | Ansible |

For a detailed feature comparison, see [IaC on Quake AI](/docs/automation/concepts/iac-comparison).

## Getting started

The fastest path from zero to a running resource:

1. [Install OpenTofu and deploy your first instance](/docs/automation/how-to/getting-started-iac): a step-by-step guide covering installation, authentication, and your first `tofu apply`.
2. Browse the [infrastructure template library](/resources/iac-templates) for common deployment patterns you can deploy or adapt. Each reference page lists when to choose that pattern and links to shared customize how-tos.
3. Set up [remote state management](/docs/automation/how-to/state-management) when you are ready to collaborate with a team.

## See also

- [Automation service overview](/docs/automation/index)
- [IaC on Quake AI](/docs/automation/concepts/iac-comparison)
- [How to get started with Infrastructure as Code](/docs/automation/how-to/getting-started-iac)
- [Infrastructure template library](/resources/iac-templates)
