# Full-Stack Application

Source: https://docs.quake.ai/resources/iac-templates/full-stack-app
Markdown: https://docs.quake.ai/resources/iac-templates/full-stack-app.md

---

# Full-stack application

This pattern composes Compute, Network, and Block Storage.

## What this template does

Provisions a complete multi-tier application stack:

- Web, application, and database servers as separate compute instances
- Cloud-init bootstraps each tier: Nginx on the web server reverse-proxies to the app server on port 8080, the app server runs a Python service that queries the database, and the db server runs MariaDB
- Private network with a router for inter-tier communication
- A block storage volume mounted at `/var/lib/mysql` on the db tier for database persistence
- Security groups isolating each tier (web exposed; app and db reachable only from the private network)
- A floating IP on the web tier for public access

Based on the existing [Full-Stack Terraform tutorial](/docs/automation/how-to/terraform-full-stack), packaged as a reusable, parameterized template.

Set `db_password` to a strong value when you apply the template. The template ships no default password.

## Component overview

<Figure caption="Three-tier architecture: web, application, and database servers on a private network with a floating IP and persistent storage.">

```d2
direction: down

internet: Internet {shape: cloud}
router: Router
fip: Floating IP

private: Private Network {
  web: Web Server {style.fill: "#fef3c7"}
  app: App Server
  db: DB Server
  volume: Data Volume {shape: cylinder}

  web -> app: :8080
  app -> db: :3306
  db -- volume
}

internet <-> router
router <-> fip
fip -> private.web
```

</Figure>

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist in your project) | required |
| `web_flavor` | Web server instance size | `s1a.small` |
| `app_flavor` | App server instance size | `s1a.medium` |
| `db_flavor` | Database instance size | `m2a.large` |
| `db_volume_size` | Database volume in GB | `50` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `db_name` | Application database name | `appdb` |
| `db_user` | Application database user | `appuser` |
| `db_password` | Password for the database user (required, no default) | _none_ |
| `dns_nameservers` | Resolvers for the private subnet | `["8.8.8.8", "8.8.4.4"]` |
| `external_network` | External network for router gateway and floating IP | `PublicStatic` |
| `private_cidr` | Address range for the private subnet | `192.168.50.0/24` |

## When to use this pattern

Provision web, application, and database instances on dedicated subnets with tier-scoped security groups. Choose [Three-Tier Application](/resources/iac-templates/three-tier-app) for the same tier model with explicit router interfaces per subnet. Add an [edge reverse proxy](/resources/iac-templates/edge-reverse-proxy) for a dedicated HTTPS entry point.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "full-stack-app", required: true },
  ]}
/>

## Template source

<TemplateSource slug="full-stack-app" />

<TemplateVariations base="full-stack-app" />

<TemplateResourceMap template="full-stack-app" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy the full-stack application template with OpenTofu](/resources/deployments/deploy-full-stack-app-template)
- [Create a full-stack application with Terraform](/docs/automation/how-to/terraform-full-stack)
- [Three-Tier Application template](/resources/iac-templates/three-tier-app)
