# Outline team knowledge base

Source: https://docs.quake.ai/resources/iac-templates/outline-docs
Markdown: https://docs.quake.ai/resources/iac-templates/outline-docs.md

---

# Outline team knowledge base

This pattern composes Compute, Network, and Block Storage into a self-hosted team wiki you run on infrastructure you control.

## What this template does

Provisions a single instance running [Outline](https://www.getoutline.com), an open-source team knowledge base (a self-hosted alternative to Notion or Confluence). Your team keeps runbooks, decisions, onboarding, and project notes on infrastructure you own:

- Compute instance that runs Outline in Docker alongside a bundled PostgreSQL and Redis (4 vCPU and 4 GiB RAM)
- Private network, subnet, router, port, and security group; a floating IP for public access
- A block volume mounted at `/var/lib/docker`, so the database, Redis, and local file uploads live on a volume you can grow rather than on the boot disk
- cloud-init installs Docker Engine, brings up PostgreSQL and Redis, and prepares Outline to start once you finish configuration

Outline's secret keys and the database password are generated on first boot and written to `/opt/outline/.env`; no credential ships with this template.

## Outline requires an auth provider

Outline has no built-in email-and-password login. It authenticates users through an external identity provider and does not serve the wiki until you configure at least one. Supported providers include OIDC (any standards-compliant identity provider), Google, Slack, and Azure AD. You set the provider, and the public `URL`, in `/opt/outline/.env` before you start the app. This is a hard requirement.

For a lighter knowledge base without the auth-provider and Redis dependencies, [BookStack](https://www.bookstackapp.com) (PHP plus MySQL, with built-in local accounts) and [Docmost](https://docmost.com) are simpler self-hosted options. This template leads with Outline because it is the closest self-hosted match for a Notion or Confluence workspace.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (Outline plus PostgreSQL and Redis runs on 4 vCPU / 4 GiB) | `s1a.medium` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `outline` |
| `volume_size` | Block volume size in GiB, mounted at `/var/lib/docker` | `20` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.46.0.0/24` |
| `app_allowed_cidr` | CIDR allowed to reach Outline on port 3000 | `10.46.0.0/24` |
| `file_storage` | Upload storage: `local` or `s3` | `local` |
| `s3_endpoint` | S3-compatible endpoint (when `file_storage` is `s3`) | `""` |
| `s3_region` | S3 region (when `file_storage` is `s3`) | `us-east-1` |
| `s3_bucket` | S3 bucket name (when `file_storage` is `s3`) | `""` |

## Finish setup after apply

cloud-init starts PostgreSQL and Redis and writes the generated secrets to `/opt/outline/.env`. Complete the setup over SSH:

1. Point a domain's DNS A record at the floating IP and put a reverse proxy (Caddy or Nginx) in front for HTTPS on 443.
2. Edit `/opt/outline/.env`: set `URL` to your public HTTPS address and fill in your auth provider (for example the `OIDC_*` block).
3. Run the database migration and start Outline:

```bash
cd /opt/outline
sudo docker compose run --rm outline yarn db:migrate
sudo docker compose up -d
```

## Access and security

Outline listens on port 3000 over plain HTTP. The security group restricts 3000 to `app_allowed_cidr`, which defaults to the private network only. Because Outline needs a public URL and an auth provider, the normal access path is a domain with HTTPS on 443 behind a reverse proxy. Ports 80 and 443 stay open for that proxy; they carry no traffic until you add one.

## File storage

The `file_storage` parameter selects where uploads go:

- `local` (default): uploads live on the data volume. No external service is needed.
- `s3`: uploads go to an S3-compatible bucket, such as Quake AI Object Storage. Set `s3_endpoint`, `s3_region`, and `s3_bucket`, then add `AWS_ACCESS_KEY_ID` and `AWS_SECRET_ACCESS_KEY` to `/opt/outline/.env` on the instance. The keys stay out of tfvars and the repo.

## When to use this pattern

Run a shared team wiki with a rich editor, collections, and search on a host you operate. Outline suits a team that already has an identity provider and wants its documentation on its own infrastructure. The bundled PostgreSQL and Redis suit a single-team knowledge base; to run them separately, point `DATABASE_URL` and `REDIS_URL` at a [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres) instance and a [Redis](/resources/iac-templates/redis-cache) instance.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "outline-docs", required: true },
  ]}
/>

## Template source

<TemplateSource slug="outline-docs" />

<TemplateResourceMap template="outline-docs" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres)
- [Redis](/resources/iac-templates/redis-cache)
- [S3 object storage](/resources/iac-templates/s3-storage-acl)
