# Edge functions

Source: https://docs.quake.ai/resources/iac-templates/edge-functions
Markdown: https://docs.quake.ai/resources/iac-templates/edge-functions.md

---

# Edge functions

This pattern composes Compute, Network, and Block Storage into a regional function gateway on infrastructure you control.

## What this template does

Provisions a single instance running [OpenFaaS faasd](https://github.com/openfaas/faasd), a single-binary FaaS gateway that uses containerd and systemd (no Kubernetes), on a floating IP:

- Compute instance sized for a modest function workload (2 vCPU and 2 GiB RAM by default)
- Private network, subnet, router, port, and security group; a floating IP on the gateway only
- A block volume mounted at `/data`, so function images, faasd state, and TLS certificates live on a volume you can grow rather than on the boot disk
- cloud-init installs faasd, generates a gateway password on first boot, deploys the `nodeinfo` starter function, and starts Caddy as the public HTTP/HTTPS front door in front of faasd on `127.0.0.1:8080`

No credential ships with this template. faasd generates the gateway basic-auth password on first boot and writes it to `/root/faasd-gateway-credentials` (readable only by root).

## Honest scope

This gateway runs in one region on a VM you operate. It is a regional function runtime, not a global edge network: Quake AI has no anycast, no global PoPs, and no first-party serverless edge. Functions execute in the region where you deploy the instance. For geographic distribution, [front the origin with a third-party CDN](/docs/network/how-to/front-with-cdn).

## Alternate engines

This template leads with OpenFaaS faasd (OpenFaaS project, single VM, systemd + containerd, the "functions on one box" appliance). [Spin / SpinKube](https://spinframework.dev) (CNCF, WebAssembly) fits when you want Wasm functions on Kubernetes; see the [Kubernetes cluster template](/resources/iac-templates/k8s-cluster) for the cluster path instead of a single VM. [Supabase Edge Runtime](https://github.com/supabase/edge-runtime) (Deno-based, MIT) fits when you already run [Supabase self-host](/resources/iac-templates/supabase-selfhost) and want Deno edge functions beside the BaaS stack.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (faasd + containerd in 2 GiB) | `s1a.small` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `edge-functions` |
| `caddy_version` | Caddy image tag for the public HTTP/HTTPS front door | `2-alpine` |
| `domain` | Public domain for automatic HTTPS; empty serves HTTP on the floating IP | `""` |
| `volume_size` | Block volume size in GiB, mounted at `/data` | `20` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.42.0.0/24` |

## Ports and access

| Port | Purpose |
| --- | --- |
| 22 | Host SSH for administration |
| 80 | HTTP entry through Caddy to faasd |
| 443 | HTTPS when `domain` is set and Caddy has obtained a certificate |
| 8080 | faasd gateway (localhost only; Caddy is the public entry) |

## Starter function and deploy workflow

On first boot, cloud-init deploys the `nodeinfo` function from the OpenFaaS store. Invoke it at `http://<floating-ip>/function/nodeinfo` (or HTTPS on your domain when `domain` is set) with basic auth (`admin` and the password from `/root/faasd-gateway-credentials`).

Deploy more functions with `faas-cli` after you SSH in and log in:

```bash
faas-cli login -u admin -p YOUR_PASSWORD --gateway http://YOUR_FLOATING_IP
faas-cli store deploy figlet
```

## When to use this pattern

Run a regional function gateway on a VM you operate so HTTP handlers execute close to your other Quake AI workloads without adopting a managed serverless edge product. Pair it with [Edge reverse proxy](/resources/iac-templates/edge-reverse-proxy) when you need TLS termination without functions, or with [API gateway](/resources/iac-templates/api-gateway) when you need rate limits and key auth in front of long-running services instead of functions.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "edge-functions", required: true },
  ]}
/>

## Template source

This is a [validated OpenTofu template](/docs/platform/validation#how-infrastructure-templates-are-checked).

<TemplateSource slug="edge-functions" />

<TemplateResourceMap template="edge-functions" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy edge functions with the edge-functions template](/resources/deployments/deploy-edge-functions-template)
- [Supabase self-host template](/resources/iac-templates/supabase-selfhost)
- [Kubernetes cluster template](/resources/iac-templates/k8s-cluster)
- [Edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy)
- [API gateway template](/resources/iac-templates/api-gateway)
- [Front with a CDN](/docs/network/how-to/front-with-cdn)
