# Deploy the three-tier application template with OpenTofu

Source: https://docs.quake.ai/resources/deployments/deploy-three-tier-app-template
Markdown: https://docs.quake.ai/resources/deployments/deploy-three-tier-app-template.md
> Stand up web, app, and database subnets with tier-specific security groups and one floating IP on the first web instance using the three-tier-app OpenTofu template.

---

# Deploy the three-tier application template with OpenTofu

Stand up separate web, application, and database subnets on one private network using the [validated OpenTofu template](/docs/platform/validation#how-infrastructure-templates-are-checked) `three-tier-app`. The template provisions infrastructure and network isolation only; you configure each tier after apply with cloud-init, configuration management, or your own deployment pipeline.

<PricingCompanion
  components={[
    { kind: "template", slug: "three-tier-app", required: true },
  ]}
/>

<Figure size="md" caption="Three-tier topology: web, app, and database subnets with one floating IP on the first web instance">

```d2
direction: right

cloud: Quake AI {
  fip: Floating IP\nweb tier only
  private: Private network {
    web_sn: Web subnet\n192.168.60.0/24 {
      web1: Web x2
    }
    app_sn: App subnet\n192.168.61.0/24 {
      app1: App x2
    }
    db_sn: DB subnet\n192.168.62.0/24 {
      db1: DB x1\n+ data volume
    }
  }
  router: Router\nto PublicStatic
}

cloud.fip -> cloud.private.web_sn.web1
cloud.router -> cloud.private
```

</Figure>

## Prerequisites

You need:

- A Quake AI account with [application credentials](/docs/tools/generate-app-credentials)
- OpenTofu 1.6.0 or later ([installation guide](https://opentofu.org/docs/intro/install/))
- OpenStack credentials sourced into the shell (`source openrc.sh`). See [the OpenStack CLI guide](/docs/tools/openstack-cli).
- An SSH key pair already uploaded to the project. See [Add an SSH key](/docs/tools/add-ssh-key).
- A copy of the `three-tier-app` template from [the template reference page](/resources/iac-templates/three-tier-app)
- Enough project quota for five instances at the default counts, one 50 GB database data volume, one router, and one floating IP

## Step 1: Configure variables

Copy `terraform.tfvars.example` to `terraform.tfvars` and set:

```hcl
key_name = "YOUR_KEY_NAME"
```

Defaults for tier counts, flavors, and subnet CIDRs are documented on the [Three-Tier Application](/resources/iac-templates/three-tier-app) reference page. Override counts or flavors in `terraform.tfvars` if your project quota is tight.

## Step 2: Apply the template

From the template directory, run:

```bash
tofu init
tofu plan
tofu apply
```

Type `yes` when prompted. At the default counts, OpenTofu creates five instances, three subnets, tier-specific security groups, and one floating IP on the first web port.

When the run finishes, run `tofu output` and note `web_floating_ip` and the private IP lists for each tier.

## Step 3: Verify subnet isolation and web-tier reachability

List the instances and their network attachments:

```bash
openstack server list --name three-tier-app -c Name -c Networks -c Status
```

Confirm the floating IP is bound to the first web port:

```bash
openstack floating ip list --floating-ip-address "$(tofu output -raw web_floating_ip)" -c "Floating IP Address" -c Port -c "Fixed IP Address"
```

The **Fixed IP Address** column should match the first address in `tofu output -json web_ips`.

Test that the web tier accepts inbound traffic on the public entrypoint:

```bash
WEB=$(tofu output -raw web_floating_ip)
nc -zv -w 5 "${WEB}" 22
```

A successful connection report confirms the floating IP routes to the first web instance. Application and database instances have no floating IP.

Optional: confirm the database data volume is attached:

```bash
openstack volume list --name three-tier-app-db-1-data -c Name -c Status -c Attached to
```

## Next steps

- [Three-Tier Application template](/resources/iac-templates/three-tier-app)
- [Full-Stack Application template](/resources/iac-templates/full-stack-app)
- [Edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy)
- [Web applications](/resources/solutions/web-applications)

## Clean up

Run `tofu destroy` from the project directory when finished. Type `yes` to confirm. Verify in the Console that all instances, data volumes, and the floating IP are gone.
