# Infisical secrets management

Source: https://docs.quake.ai/resources/iac-templates/infisical-secrets
Markdown: https://docs.quake.ai/resources/iac-templates/infisical-secrets.md

---

# Infisical secrets management

This pattern composes Compute, Network, and Block Storage into a self-hosted secrets-management platform you run on infrastructure you control.

## What this template does

Provisions a single instance running [Infisical](https://infisical.com), an open-source secrets-management platform (a self-hosted alternative to Doppler or 1Password Secrets). Your team stores API keys, database credentials, and other secrets on infrastructure you own:

- Compute instance that runs Infisical in Docker alongside a bundled PostgreSQL and Redis (4 vCPU and 4 GiB RAM)
- Private network, subnet, router, port, and security group; a floating IP for public access
- A block volume mounted at `/var/lib/docker`, so the database and Redis data live on a volume you can grow rather than on the boot disk
- cloud-init installs Docker Engine, brings up PostgreSQL and Redis, and prepares Infisical to start once you finish configuration

Infisical's `ENCRYPTION_KEY`, `AUTH_SECRET`, and the database password are generated on first boot and written to `/opt/infisical/.env`; no credential ships with this template.

## Infisical has built-in login, no auth provider required

Unlike some of the other self-hosted ops tools in this library, Infisical ships built-in email-and-password login. It serves the app and lets you sign up the first admin account as soon as you set `SITE_URL` and start the container, with no external identity provider to configure first.

For a lighter alternative without a Postgres and Redis dependency, [OpenBao](https://openbao.org) (the open-source Vault fork) covers similar ground with a different operational model: a single binary, no bundled web UI by default. This template leads with Infisical because of its built-in UI, project and environment model, and CLI/SDK ecosystem.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (Infisical plus PostgreSQL and Redis runs on 4 vCPU / 4 GiB) | `s1a.medium` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `infisical` |
| `volume_size` | Block volume size in GiB, mounted at `/var/lib/docker` | `20` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.47.0.0/24` |
| `app_allowed_cidr` | CIDR allowed to reach Infisical on port 8080 | `10.47.0.0/24` |

## Finish setup after apply

cloud-init starts PostgreSQL and Redis and writes the generated secrets to `/opt/infisical/.env`. Complete the setup over SSH:

1. Point a domain's DNS A record at the floating IP and put a reverse proxy (Caddy or Nginx) in front for HTTPS on 443.
2. Edit `/opt/infisical/.env`: set `SITE_URL` to your public HTTPS address.
3. Start Infisical:

```bash
cd /opt/infisical
sudo docker compose up -d
```

## Back up ENCRYPTION_KEY

`ENCRYPTION_KEY` encrypts every secret Infisical stores at rest. Losing it makes every stored secret permanently unrecoverable; there is no recovery path. Copy `/opt/infisical/.env` to a secure location outside this instance immediately after first boot, before you store any real secrets.

## Access and security

Infisical listens on port 8080 over plain HTTP. The security group restricts 8080 to `app_allowed_cidr`, which defaults to the private network only. Because Infisical needs a public URL for auth callbacks and CLI/SDK logins, the normal access path is a domain with HTTPS on 443 behind a reverse proxy. Ports 80 and 443 stay open for that proxy; they carry no traffic until you add one.

## When to use this pattern

Centralize secrets for a team or project with versioning, environments, and access control, on a host you operate. The bundled PostgreSQL and Redis suit a single-team deployment; to run them separately, point `DB_CONNECTION_URI` and `REDIS_URL` at a [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres) instance and a [Redis](/resources/iac-templates/redis-cache) instance. The [`quake.yaml` launch manifest](/resources/ai-assisted-development/quake-yaml#secrets) declares secret names but never values; Infisical is a natural runtime secret store to inject those values from at deploy time.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "infisical-secrets", required: true },
  ]}
/>

## Template source

<TemplateSource slug="infisical-secrets" />

<TemplateResourceMap template="infisical-secrets" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres)
- [Redis](/resources/iac-templates/redis-cache)
- [quake.yaml reference: Secrets](/resources/ai-assisted-development/quake-yaml#secrets)
