# Containerized App on Compute

Source: https://docs.quake.ai/resources/iac-templates/containerized-app
Markdown: https://docs.quake.ai/resources/iac-templates/containerized-app.md

---

# Containerized app on compute

This pattern composes Compute and Network.

Golden-path OpenTofu template for `quake.yaml` manifests with `runtime: container`. Provisions a CPU instance with Docker, pulls a container image, and publishes it on a floating IP.

## What this template does

Provisions a single compute instance for container workloads:

- Private network, subnet, router, and neutron port
- Security group allowing SSH and the published container port
- Volume-backed boot disk
- Floating IP for public access
- Cloud-init installs Docker, pulls `container_image`, and runs the container with host port mapping and any `container_env` variables

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist in your project) | No default |
| `flavor_name` | Instance size | `s1a.small` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Resource name prefix | `containerized-app` |
| `container_image` | Container image reference | `nginx:alpine` |
| `container_env` | Environment variables injected into the container | `{}` |
| `container_port` | Port inside the container | `80` |
| `host_port` | Port published on the instance | `80` |
| `external_network` | External network for floating IP | `PublicEphemeral` |
| `private_cidr` | Private subnet CIDR | `10.10.10.0/24` |

## When to use this pattern

Deploy a single VM prepped for Docker workloads on a private network with a floating IP. Add an [edge reverse proxy](/resources/iac-templates/edge-reverse-proxy) or [API gateway](/resources/iac-templates/api-gateway) when you need a dedicated entry point in front of one or more container hosts.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "containerized-app", required: true },
  ]}
/>

## Template source

<TemplateSource slug="containerized-app" />

<TemplateResourceMap template="containerized-app" format="opentofu" />

## quake.yaml mapping

| Manifest field | Template parameter |
| --- | --- |
| `runtime: container` | Resolves to slug `containerized-app` |
| `environments.production.resources: cpu-standard` | `flavor_name = "m2a.large"` |
| `environments.preview.resources: cpu-small` | `flavor_name = "s1a.small"` |
| `source.build: dockerfile` | Build in CI, push to a registry, set `container_image` before apply |
| `secrets` and resolved `services` outputs | `container_env` map injected into the running container |

Branch-to-environment routing (`production` on `main`, `preview` on other branches) is described in the template's `README`, included in the template source on this page.

The launch handoff plan populates `container_env` from `quake.yaml` secret names (you supply the values) and from the outputs of service templates applied earlier in the plan. For the POC, `container_env` values pass as `docker run -e` flags, which are visible in the instance process list. Source production secrets from a secret store.

## Outputs

| Output | Description |
| --- | --- |
| `floating_ip` | Public floating IP assigned to the instance |
| `private_ip` | Private IP address of the instance |
| `container_url` | HTTP URL for the published container (floating IP and host port) |
| `instance_id` | Compute instance ID |

Read `container_url` after apply to verify the deployment and record it in the launch evidence bundle.

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy a containerized web application](/docs/quickstart/deploy-containerized-app)
- [Simple VM with Floating IP](/resources/iac-templates/simple-vm)
