# Mattermost team chat

Source: https://docs.quake.ai/resources/iac-templates/mattermost-team-chat
Markdown: https://docs.quake.ai/resources/iac-templates/mattermost-team-chat.md

---

# Mattermost team chat

This pattern composes Compute, Network, and Block Storage into a self-hosted team-chat platform for a team, on infrastructure you control.

## What this template does

Provisions a single instance running [Mattermost](https://mattermost.com) Team Edition, an open-source team-chat platform (a self-hosted alternative to Slack). Your team communicates over channels, direct messages, and integrations on infrastructure you own:

- Compute instance that runs Mattermost in Docker alongside a bundled PostgreSQL (4 vCPU and 4 GiB RAM, a heavier floor than the lighter ops-tools templates in this library)
- Private network, subnet, router, port, and security group; a floating IP for public access
- A block volume mounted at `/var/lib/docker`, so the database data and every Mattermost data directory (config, data, logs, plugins, search indexes) live on a volume you can grow
- cloud-init installs Docker Engine, brings up PostgreSQL, and prepares Mattermost to start once you finish configuration

The PostgreSQL password is generated on first boot and written to `/opt/mattermost/.env`; no credential ships with this template.

## Mattermost needs a public URL before it is fully usable

Like [Infisical](/resources/iac-templates/infisical-secrets) and [Plane](/resources/iac-templates/plane-project-management), Mattermost's `MM_SERVICESETTINGS_SITEURL` must point at a real public HTTPS address before invite links, OAuth, and calls work. This template holds the Mattermost app container until you finish that configuration; PostgreSQL starts immediately.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (Mattermost plus PostgreSQL runs on 4 vCPU / 4 GiB for a small-to-mid team) | `s1a.medium` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `mattermost` |
| `volume_size` | Block volume size in GiB, mounted at `/var/lib/docker` | `20` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.55.0.0/24` |
| `app_allowed_cidr` | CIDR allowed to reach Mattermost on port 8065 | `10.55.0.0/24` |

## Finish setup after apply

cloud-init starts PostgreSQL and writes the generated database password to `/opt/mattermost/.env`. Complete the setup over SSH:

1. Point a domain's DNS A record at the floating IP and put a reverse proxy (Caddy or Nginx) in front for HTTPS on 443.
2. Edit `/opt/mattermost/.env`: set `MM_SERVICESETTINGS_SITEURL` to your public HTTPS address.
3. Start Mattermost:

```bash
cd /opt/mattermost
sudo docker compose up -d
```

4. Open the site URL and sign up the first admin account, which becomes the System Console admin.

## Access and security

Mattermost listens on port 8065 over plain HTTP. The security group restricts 8065 to `app_allowed_cidr`, which defaults to the private network only. Because Mattermost needs a public URL for invite links, OAuth, and calls, the normal access path is a domain with HTTPS on 443 behind a reverse proxy. Ports 80 and 443 stay open for that proxy; they carry no traffic until you add one.

## When to use this pattern

Run team chat and channel-based communication for a team on a host you operate. This template's default sizing suits a small-to-mid team; Mattermost's own scaling guidance recommends significantly more compute for large enterprise deployments, and splitting PostgreSQL onto its own instance as the team grows. To run the database separately from the start, point `MM_SQLSETTINGS_DATASOURCE` at a [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres) instance.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "mattermost-team-chat", required: true },
  ]}
/>

## Template source

<TemplateSource slug="mattermost-team-chat" />

<TemplateResourceMap template="mattermost-team-chat" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres)
- [Infisical secrets management](/resources/iac-templates/infisical-secrets)
