# Appsmith internal tools

Source: https://docs.quake.ai/resources/iac-templates/appsmith-internal-tools
Markdown: https://docs.quake.ai/resources/iac-templates/appsmith-internal-tools.md

---

# Appsmith internal tools

This pattern composes Compute, Network, and Block Storage into a self-hosted low-code platform for internal tools and admin panels, on infrastructure you control.

## What this template does

Provisions a single instance running [Appsmith](https://www.appsmith.com) Community Edition, an open-source low-code platform (a self-hosted alternative to Retool). Your team builds internal tools and admin panels on infrastructure you own:

- Compute instance that runs Appsmith's single fat container: the app server, an embedded MongoDB, and an embedded Redis, all in one image (4 vCPU and 4 GiB RAM)
- Private network, subnet, router, port, and security group; a floating IP for public access
- A block volume mounted at `/var/lib/docker`, holding the `/appsmith-stacks` bind mount where all persistent state lives
- cloud-init installs Docker Engine and starts the container automatically; no manual configuration step blocks first login

`APPSMITH_ENCRYPTION_PASSWORD` and `APPSMITH_ENCRYPTION_SALT` are generated on first boot and written to `/opt/appsmith/.env`; no credential ships with this template.

## A single fat container, unlike the other multi-container ops tools

Appsmith Community Edition's documented self-host path is one container that bundles the app server, an embedded MongoDB, and an embedded Redis via a supervisor process, closer in shape to [Uptime Kuma](/resources/iac-templates/uptime-kuma)'s single-container simplicity than to [Infisical](/resources/iac-templates/infisical-secrets) or [Plane](/resources/iac-templates/plane-project-management)'s separate datastore containers. This template uses the open-source Community Edition image (`appsmith-ce`) rather than the Enterprise Edition image the Docker Hub listing recommends by default.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (the fat container runs on 4 vCPU / 4 GiB) | `s1a.medium` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `appsmith` |
| `volume_size` | Block volume size in GiB, mounted at `/var/lib/docker` | `20` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.53.0.0/24` |
| `app_allowed_cidr` | CIDR allowed to reach Appsmith on port 8080 | `10.53.0.0/24` |

## Finish setup after apply

cloud-init starts the fat container immediately; no held-back service waits on manual configuration:

1. Open the app at `app_url` (or tunnel over SSH to port 8080) and sign up the first admin account.
2. For production use, point a domain's DNS A record at the floating IP, put a reverse proxy (Caddy or Nginx) in front for HTTPS on 443, and route it to port 8080.

## Back up the encryption password and salt

`APPSMITH_ENCRYPTION_PASSWORD` and `APPSMITH_ENCRYPTION_SALT` in `/opt/appsmith/.env` encrypt stored datasource credentials at rest. Losing them makes stored datasource credentials unrecoverable. Copy `/opt/appsmith/.env` to a secure location outside this instance immediately after first boot, before you connect any real datasource.

## Access and security

Appsmith's internal port 80 is remapped to 8080 so a host-level reverse proxy can own ports 80 and 443 for the public domain. The security group restricts 8080 to `app_allowed_cidr`, which defaults to the private network only. Ports 80 and 443 stay open for a reverse proxy you add for production use; they carry no traffic until you add one.

## When to use this pattern

Build internal tools, admin panels, and database-backed UIs for a team on a host you operate. All persistent state, including the embedded database, lives under `/appsmith-stacks` on the attached volume: there is no separate datastore to point elsewhere.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "appsmith-internal-tools", required: true },
  ]}
/>

## Template source

<TemplateSource slug="appsmith-internal-tools" />

<TemplateResourceMap template="appsmith-internal-tools" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres)
- [Uptime Kuma status and uptime](/resources/iac-templates/uptime-kuma)
- [Infisical secrets management](/resources/iac-templates/infisical-secrets)
