Deploy edge functions with the edge-functions template
Deployment
Deploy edge functions with the edge-functions template
Stand up an OpenFaaS faasd function gateway on one Quake AI instance using the validated OpenTofu templateedge-functions. You apply the template, read the generated gateway credentials, invoke the starter function over the floating IP, deploy an additional function from the OpenFaaS store, add a secret and consume it from a function, schedule a periodic invocation with cron on the gateway host, and optionally point a domain for automatic TLS.
You operate the gateway yourself on a regional VM. Functions execute in that region; this is not a global edge network like Cloudflare Workers or Vercel Edge Functions.
Click to zoom
What you'll build: faasd on a gateway instance with a floating IP runs containerized functions behind Caddy on ports 80 and 443
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
Functions
s1a.small · 2 shared vCPU, 2 GiB RAM, 0.5 Gbps
$16.50/mo
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
$0.00
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
$0.00
Pricing data last validated: . For current rates, check quake.ai/pricing.
faas-cli installed on your workstation, or willingness to run faas-cli commands over SSH on the gateway host (the faasd install script places faas-cli on the instance). See OpenFaaS CLI installation.
A domain you can point at the gateway floating IP when you enable TLS (optional for the HTTP verification steps below).
Copy the template's example variables file and set key_name. Leave domain empty so Caddy serves plain HTTP on port 80 while you verify functions:
bash
cp terraform.tfvars.example terraform.tfvars
HCL
key_name = "YOUR_KEY_NAME"
Initialize, preview, and apply:
bash
tofu inittofu plantofu apply
OpenTofu provisions a private network, router, security group, data volume, gateway instance, and floating IP. cloud-init installs faasd via the upstream install script, generates a gateway password on first boot, deploys the nodeinfo starter function from the OpenFaaS store, and starts Caddy as the public front door.
The response should be JSON describing the gateway host (hostname, platform, CPU count, and related fields). If you get 401 Unauthorized, recheck the password from step 2. If you get 404, cloud-init may still be deploying; wait two minutes and retry.
Step 4: Deploy a function from the OpenFaaS store#
Log in to the gateway with faas-cli from your workstation (replace the gateway URL with your floating IP):
On faasd, secrets are files under /var/openfaas/secrets/ inside function containers. Store functions like figlet do not mount custom secrets by default; consume the secret in the cron step by reading it on the host and passing the value as the request body:
The response should be ASCII art for cron secret payload, which confirms the secret value reached the function invocation path.
Step 6: Schedule a cron invocation on the gateway host#
faasd on a single VM does not ship a separate cron connector. Schedule periodic invocations with a root crontab entry on the gateway that reads the secret and calls figlet on localhost:
The log should show successful HTTP responses from repeated figlet invocations. Each line corresponds to one cron tick.
Step 7: Point a domain and enable HTTPS (optional)#
Skip this step if HTTP on the floating IP is enough for your test. To enable automatic TLS with Caddy in front of faasd:
Create a DNS A record for your domain (for example functions.example.com) pointing at YOUR_FLOATING_IP. Follow How to point a domain at a Quake AI resource. Wait until it resolves:
bash
dig +short functions.example.com
Set domain in terraform.tfvars and re-apply:
HCL
domain = "functions.example.com"
bash
tofu apply
cloud-init switches to the HTTPS branch: Caddy terminates TLS on ports 80 and 443 and forwards to faasd on 127.0.0.1:8080. Wait three to five minutes for Caddy to obtain a Let's Encrypt certificate.
This gateway runs in one region on a VM you operate. It executes functions in that region on containerd via faasd. It is not a global edge network: Quake AI has no anycast, no global PoPs, and no first-party serverless edge. For geographic distribution, front workloads with a third-party CDN.