# Three-Tier Application

Source: https://docs.quake.ai/resources/iac-templates/three-tier-app
Markdown: https://docs.quake.ai/resources/iac-templates/three-tier-app.md

---

# Three-tier application

This pattern composes Compute, Network, and Block Storage.

## What this template does

Provisions a classic three-tier architecture with strict network isolation:

- **Web tier**: web instances on the web subnet; the first web instance carries a floating IP for public entry. The template puts no load balancer in front of the tier, so additional web instances are reachable only from inside the network.
- **Application tier**: business logic instances on a private subnet
- **Database tier**: data instances on an isolated subnet with block storage

The template provisions the infrastructure and tier isolation; it installs no application, runtime, or database software. Bring your own configuration (for example with cloud-init or a configuration-management tool) for each tier.

Each tier lives on its own subnet with security groups enforcing that traffic flows only web → app → database. No direct public access to application or database tiers.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist in your project) | required |
| `web_count` | Number of web instances | `2` |
| `app_count` | Number of app instances | `2` |
| `db_count` | Number of database instances | `1` |
| `web_flavor` | Web tier instance size | `s1a.small` |
| `app_flavor` | App tier instance size | `m2a.large` |
| `db_flavor` | Database tier instance size | `m2a.xlarge` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `external_network` | External network for router gateway and floating IP | `PublicStatic` |
| `web_cidr` | CIDR for the web subnet | `192.168.60.0/24` |
| `app_cidr` | CIDR for the application subnet | `192.168.61.0/24` |
| `db_cidr` | CIDR for the database subnet | `192.168.62.0/24` |
| `db_volume_size` | Size in GB for each database data volume | `50` |

## When to use this pattern

Use this pattern for classic web, app, and database tiers with per-tier subnets and security groups. Choose [Full-Stack Application](/resources/iac-templates/full-stack-app) for a similar layout with cloud-init driven setup. Put an [edge reverse proxy](/resources/iac-templates/edge-reverse-proxy) or [API gateway](/resources/iac-templates/api-gateway) in front when the web tier needs a dedicated public entry point.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "three-tier-app", required: true },
  ]}
/>

## Template source

<TemplateSource slug="three-tier-app" />

<TemplateVariations base="three-tier-app" />

<TemplateResourceMap template="three-tier-app" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy the three-tier application template with OpenTofu](/resources/deployments/deploy-three-tier-app-template): end-to-end tutorial that applies this template, verifies tier isolation, and tears the stack down
- [Full-Stack Application template](/resources/iac-templates/full-stack-app)
- [Edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy)
