Deploy Coolify with the coolify-host template
Deploy Coolify with the coolify-host template
Stand up Coolify, an open-source deploy platform, on a single Quake AI instance using the validated OpenTofu template coolify-host. You apply the template, complete Coolify's first-boot setup, connect a Git repository, deploy a Next.js app, add a Coolify-managed Postgres database and wire it to the app, and serve the app over your own domain with automatic HTTPS.
Coolify gives you a git-push build-and-deploy loop, branch previews, and managed database add-ons on a VM you operate. You run the platform yourself; this is not a managed service.
Monthly cost estimate
Pricing calculator ↗Sized as a custom package on shared vCPU.
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
Coolify host
s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps
Runs Coolify in Docker, along with the Postgres and Redis add-ons it provisions for the apps you deploy.
Coolify's baseline is 2 vCPU and 2 GiB RAM. The default size doubles that to leave headroom for image builds and the add-on containers.
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Included in baseline
s1a.medium
4 shared vCPU, 4 GiB RAM, 0.5 Gbps
Compute + RAM rate basis
4 vCPU + 4 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.
Block storage (80 GiB)
80 GiB at $0.08/GiB/mo
Public IP (included)
1 included with the custom package
Package promotional discount
Flat −$5.00/mo on the custom package (same promotion as named plans).
Included at no charge
These line items are zero on Quake AI. Many other providers meter them separately.
Data transfer (inbound and outbound)
Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.
AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.
Learn morePrivate networking
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
Pricing data last validated: . For current rates, check quake.ai/pricing.
Prerequisites#
You need:
- OpenTofu 1.6.0 or later (or Terraform 1.6.0 or later) installed locally.
- Your OpenStack credentials sourced into the shell (
source openrc.sh). See the OpenStack CLI guide. - An SSH keypair that already exists in your project. Record its name for the
key_namevariable. - A Git repository holding a deployable app. This walkthrough uses a Next.js app; any repo Coolify can build works. If the repository is private, have a GitHub, GitLab, or other Git provider account ready so you can authorize Coolify.
- A copy of the
coolify-hosttemplate directory from the template reference page. - Your workstation's public IP address, so you can open the dashboard port to it. Find it with
curl -sS https://api.ipify.org.
A domain is optional. You add it in step 6 to serve the app over HTTPS.
Step 1: Set the variables and apply the template#
Coolify's dashboard listens on port 8000 over plain HTTP. The template's security group restricts port 8000 to dashboard_allowed_cidr, which defaults to the private network only, so the raw dashboard stays off the public internet. To reach the dashboard from your workstation for first-boot setup, set dashboard_allowed_cidr to your own address.
Copy the template's example variables file and open it:
cp terraform.tfvars.example terraform.tfvarsSet key_name to the SSH keypair already in your project, and dashboard_allowed_cidr to your workstation's public IP with a /32 suffix:
key_name = "YOUR_KEY_NAME"
dashboard_allowed_cidr = "YOUR_IP/32"Initialize the working directory, preview the plan, and apply:
tofu init
tofu plan
tofu applyOpenTofu provisions a private network, a router, a security group, a block volume mounted at /var/lib/docker, an instance, and a floating IP. On first boot, cloud-init mounts the data volume, then runs Coolify's official installer, which bootstraps Docker Engine and starts the dashboard on port 8000.
When the apply finishes, read the outputs:
tofu outputRecord floating_ip and dashboard_url.
Step 2: Complete Coolify's first-boot setup#
The installer generates its own secrets on first boot and does not ship a default password. You set the admin account the first time you open the dashboard.
The installer takes a minute or two after the instance reaches ACTIVE. Open the dashboard_url (for example http://YOUR_FLOATING_IP:8000) in your browser. If the page does not load yet, wait and retry; you can watch progress over SSH:
ssh ubuntu@YOUR_FLOATING_IP "sudo docker ps --filter name=coolify"When the registration page appears:
- Enter a name, email, and a strong password to create the root account. This account administers the Coolify instance.
- Sign in. Coolify opens to the dashboard and creates a default project and a
localhostserver entry that points at the instance Coolify runs on.
Step 3: Connect a Git repository#
Coolify builds your app from source it pulls from a Git repository.
- In the dashboard, go to Sources and connect your Git provider, or use a public repository URL directly. For a private repository, follow Coolify's prompt to install its GitHub App (or add a deploy key for GitLab and others) so Coolify can clone the repo and register a webhook for push-to-deploy.
- Confirm the source shows as connected. Coolify can now list repositories you authorized.
For a public repository, you can skip the provider integration and paste the repository URL when you create the application in the next step.
Step 4: Deploy a Next.js app#
- Open your project and select + New > Application.
- Choose the Git source you connected (or Public Repository and paste the URL), then pick the repository and branch.
- Coolify detects the build pack. For a standard Next.js app, Nixpacks builds it without configuration. If your repository ships a
Dockerfile, select the Dockerfile build pack instead. - Set the Port the app listens on to
3000, the Next.js default. - Select Deploy. Coolify clones the repo, builds the image on the instance, and starts the container.
Watch the build and deploy logs stream in the dashboard. When the deployment finishes, Coolify shows the application as running and exposes it on a generated URL. Open that URL to confirm the app responds.
Step 5: Add a managed Postgres and wire it to the app#
Coolify provisions databases as managed resources alongside your apps.
- In your project, select + New > Database > PostgreSQL. Coolify starts a Postgres container and generates a username, password, and database name.
- Open the database's page and copy the internal connection URL. It has the form
postgres://USERNAME:PASSWORD@DATABASE_HOST:5432/DATABASE_NAME, whereDATABASE_HOSTis the internal service name Coolify assigns. The internal URL keeps database traffic on the instance's Docker network rather than over the public internet. - Go back to your application, open Environment Variables, and add the connection string as
DATABASE_URL:
DATABASE_URL=postgres://USERNAME:PASSWORD@DATABASE_HOST:5432/DATABASE_NAME- Redeploy the application so it picks up the new variable. Coolify recreates the app container with
DATABASE_URLin its environment, where your Next.js data layer reads it.
Your app and database now run as two containers on the same instance, talking over Coolify's internal network.
Step 6: Serve the app over your domain with HTTPS#
Coolify's built-in proxy obtains and renews a TLS certificate automatically once a domain resolves to the instance.
- Create a DNS A record for your domain (for example
app.example.com) pointing atYOUR_FLOATING_IP. Follow How to point a domain at a Quake AI resource. Wait until the record resolves:
dig +short app.example.comThe command returns your floating IP once the record propagates.
- In the application's settings, set the Domain (FQDN) to
https://app.example.comand save. - Redeploy the application. The proxy requests a certificate from Let's Encrypt and serves the app over HTTPS. Open
https://app.example.comto confirm the padlock.
Ports 80 and 443 are already open in the template's security group to carry the apps Coolify deploys, so no infrastructure change is needed. For background on how certificate issuance and renewal work, see How to issue and auto-renew a TLS certificate with Let's Encrypt. To move the dashboard itself onto HTTPS, set a domain for Coolify under its instance settings the same way.
What you built#
- Applied the
coolify-hosttemplate to provision a network, security group, data volume, instance, and floating IP, and let cloud-init install Coolify - Completed first-boot setup by creating the Coolify admin account
- Connected a Git repository and deployed a Next.js app that Coolify built from source
- Added a managed Postgres and injected its connection string as
DATABASE_URL - Served the app over HTTPS by pointing a domain at the floating IP and letting Coolify's proxy obtain a certificate
Scope of this deployment#
This template runs a single-VM origin, not a global edge deployment. The instance is CPU-only, and there is no native CDN. If you need edge caching for static or incrementally regenerated assets, put a third-party CDN in front of the floating IP. You operate the instance, Coolify, the deployed containers, and the database yourself: back them up, patch them, and watch their resource use as you add apps.
Next steps#
- Deploy a Next.js app with the nextjs-app template: run a single Next.js container directly on a VM without the platform layer
- self-managed Postgres template: run Postgres as a standalone instance when you outgrow a co-located database container
- How to store application secrets and inject them at runtime: move database and API credentials out of plain environment variables
- Security hardening checklist: tighten SSH access and exposure before you serve real traffic
- Coolify host template: the template reference, parameters, and resource map
Clean up#
When you no longer need the deployment, destroy everything the template created:
tofu destroyThen remove the DNS A record you created in step 6. Because Coolify, its apps, and the Postgres data all live on the instance and its attached volume, tofu destroy removes them along with the infrastructure. Export anything you want to keep before you destroy.
See Also
Instances
Prerequisite
Migrate a Docker container app from AWS to Quake AI
Shares: Docker, Containers
Deploy Airbyte with the airbyte template
Shares: Docker, Containers
Deploy Airflow with the airflow template
Shares: Docker, Containers
Deploy Umami with the analytics-umami template
Shares: Docker, Containers