# Deploy the audio post-production worker template with OpenTofu

Source: https://docs.quake.ai/resources/deployments/deploy-audio-worker-template
Markdown: https://docs.quake.ai/resources/deployments/deploy-audio-worker-template.md
> Stand up a CPU FFmpeg worker that polls an input bucket and writes mastered MP3 files to an output bucket using the audio-worker OpenTofu template.

---

# Deploy the audio post-production worker template with OpenTofu

Stand up a CPU FFmpeg worker that polls an input bucket and writes mastered MP3 files to an output bucket using the [validated OpenTofu template](/docs/platform/validation#how-infrastructure-templates-are-checked) `audio-worker`. The worker runs on a private subnet with no floating IP; it reaches Object Storage over outbound HTTPS.

<PricingCompanion
  components={[
    { kind: "template", slug: "audio-worker", required: true },
  ]}
/>

<Figure size="md" caption="Audio worker topology: input and output buckets, egress-only CPU worker on a private network, no floating IP">

```d2
direction: right

cloud: Quake AI {
  input: Input bucket\nraw audio
  output: Output bucket\nmastered MP3
  worker: CPU worker\nFFmpeg poll loop
  private: Private network\nno floating IP
}

cloud.worker -> cloud.input: poll
cloud.worker -> cloud.output: write MP3
```

</Figure>

## Prerequisites

You need:

- A Quake AI account with [application credentials](/docs/tools/generate-app-credentials)
- OpenTofu 1.6.0 or later ([installation guide](https://opentofu.org/docs/intro/install/))
- The AWS CLI installed ([installation guide](https://docs.aws.amazon.com/cli/latest/userguide/getting-started-install.html))
- OpenStack credentials sourced into the shell for minting EC2-compatible keys. See [the OpenStack CLI guide](/docs/tools/openstack-cli).
- A copy of the `audio-worker` template from [the template reference page](/resources/iac-templates/audio-worker)
- Enough project quota for one `c2a.large` instance, one 40 GB boot volume, one private network, one router, and two Object Storage buckets

## Step 1: Mint credentials and configure variables

Mint EC2-compatible credentials and export the standard AWS variables:

```bash
openstack ec2 credentials create
export AWS_ACCESS_KEY_ID=YOUR_ACCESS_KEY
export AWS_SECRET_ACCESS_KEY=YOUR_SECRET_KEY
export AWS_ENDPOINT_URL_S3=https://object.us-east-1.rumble.cloud
```

Copy `terraform.tfvars.example` to `terraform.tfvars` and set:

```hcl
key_name           = "YOUR_KEY_NAME"
input_bucket_name  = "YOUR_PROJECT_AUDIO_IN"
output_bucket_name = "YOUR_PROJECT_AUDIO_OUT"

s3_access_key = "YOUR_ACCESS_KEY"
s3_secret_key = "YOUR_SECRET_KEY"
```

Pick globally unique bucket names within your project. Defaults for `worker_flavor`, `poll_interval_seconds`, and `target_lufs` are documented on the [Audio post-production worker](/resources/iac-templates/audio-worker) reference page.

## Step 2: Apply the template

From the template directory, run:

```bash
tofu init
tofu plan
tofu apply
```

Type `yes` when prompted. Provisioning takes a few minutes while cloud-init installs FFmpeg and starts the worker service.

When the run finishes, note `input_bucket` and `output_bucket` from the outputs. The template allocates zero floating IPs by default.

## Step 3: Verify loudness normalization

Upload a short audio file to the input bucket. The worker accepts `.wav`, `.flac`, `.mp3`, `.m4a`, `.aac`, and `.ogg` keys:

```bash
ffmpeg -f lavfi -i "sine=frequency=440:duration=3" -ar 44100 /tmp/deploy-tone.wav
aws s3 cp /tmp/deploy-tone.wav "s3://$(tofu output -raw input_bucket)/deploy-tone.wav" \
  --endpoint-url "$AWS_ENDPOINT_URL_S3"
```

Wait at least one poll interval (60 seconds by default) for the worker to process the file. List the output bucket:

```bash
aws s3 ls "s3://$(tofu output -raw output_bucket)/" --endpoint-url "$AWS_ENDPOINT_URL_S3"
```

You should see `deploy-tone-master.mp3`. Download it to confirm:

```bash
aws s3 cp "s3://$(tofu output -raw output_bucket)/deploy-tone-master.mp3" /tmp/deploy-tone-master.mp3 \
  --endpoint-url "$AWS_ENDPOINT_URL_S3"
file /tmp/deploy-tone-master.mp3
```

The `file` command should report an MP3 audio stream. If nothing appears after two poll intervals, confirm the worker instance status is **Active** in the Console.

## Next steps

- [Audio post-production worker template](/resources/iac-templates/audio-worker)
- [Podcast and audio publishing](/resources/solutions/podcast-and-audio-publishing)
- [Customize template image or flavor](/docs/automation/how-to/customize-template-image-flavor)
- [S3 Storage with ACLs template](/resources/iac-templates/s3-storage-acl)

## Clean up

Empty both buckets, then run `tofu destroy` from the project directory:

```bash
aws s3 rm "s3://$(tofu output -raw input_bucket)" --recursive --endpoint-url "$AWS_ENDPOINT_URL_S3"
aws s3 rm "s3://$(tofu output -raw output_bucket)" --recursive --endpoint-url "$AWS_ENDPOINT_URL_S3"
tofu destroy
```

Delete the EC2-compatible credential with `openstack ec2 credentials delete YOUR_ACCESS_KEY` if you created one only for this deployment.
