# Unleash feature flags

Source: https://docs.quake.ai/resources/iac-templates/unleash-feature-flags
Markdown: https://docs.quake.ai/resources/iac-templates/unleash-feature-flags.md

---

# Unleash feature flags

This pattern composes Compute, Network, and Block Storage into a self-hosted feature-flags and experimentation platform you run on infrastructure you control.

## What this template does

Provisions a single instance running [Unleash](https://www.getunleash.io), an open-source feature-flags platform (a self-hosted alternative to LaunchDarkly or Flagsmith). Your team rolls out flags, gradual releases, and A/B experiments on infrastructure you own:

- Compute instance that runs Unleash in Docker alongside a bundled PostgreSQL (4 vCPU and 4 GiB RAM)
- Private network, subnet, router, port, and security group; a floating IP for public access
- A block volume mounted at `/var/lib/docker`, so the feature-flags data lives on a volume you can grow rather than on the boot disk
- cloud-init installs Docker Engine and starts both containers automatically; no manual configuration step blocks first login

The PostgreSQL password is generated on first boot and written to `/opt/unleash/.env`; no credential ships with this template.

## The simplest ops-tools template in this library

Unlike [Infisical](/resources/iac-templates/infisical-secrets) or [Plane](/resources/iac-templates/plane-project-management), Unleash has no encryption key to back up and no auth-callback URL that blocks first boot: `UNLEASH_URL` only affects links in outgoing emails and integrations. The app is reachable immediately after boot with a default local admin login (`admin` / `unleash4all`) that you change on first access.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (Unleash plus PostgreSQL runs on 4 vCPU / 4 GiB) | `s1a.medium` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `unleash` |
| `volume_size` | Block volume size in GiB, mounted at `/var/lib/docker` | `15` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.52.0.0/24` |
| `app_allowed_cidr` | CIDR allowed to reach Unleash on port 4242 | `10.52.0.0/24` |

## Finish setup after apply

cloud-init starts PostgreSQL and Unleash together; no held-back service waits on manual configuration:

1. Open the app at `app_url` (or tunnel over SSH to port 4242) and log in with the default admin credentials.
2. Change the admin password immediately.
3. For production use, point a domain's DNS A record at the floating IP, put a reverse proxy (Caddy or Nginx) in front for HTTPS on 443, and edit `/opt/unleash/.env` to set `UNLEASH_URL` to your public HTTPS address.

## Access and security

Unleash listens on port 4242 over plain HTTP. The security group restricts 4242 to `app_allowed_cidr`, which defaults to the private network only. Ports 80 and 443 stay open for a reverse proxy you add for production use; they carry no traffic until you add one.

## When to use this pattern

Roll out feature flags, gradual releases, and experiments for a team on a host you operate. The bundled PostgreSQL suits a single-team deployment; to run it separately, point `DATABASE_HOST` and the related `DATABASE_*` variables at a [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres) instance.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "unleash-feature-flags", required: true },
  ]}
/>

## Template source

<TemplateSource slug="unleash-feature-flags" />

<TemplateResourceMap template="unleash-feature-flags" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres)
- [Infisical secrets management](/resources/iac-templates/infisical-secrets)
- [Plane project management](/resources/iac-templates/plane-project-management)
