This Quake AI feature maps to Google Cloud’s Artifact Registry.
Deploy a private container registry with OpenTofu
Stand up Harbor, an open-source container registry, on a single Quake AI instance using the validated OpenTofu templateharbor-registry. You run it yourself; this is a self-hosted registry you operate, with projects, role-based access control, and Trivy vulnerability scanning by default.
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
Harbor
s1a.large · 8 shared vCPU, 8 GiB RAM, 0.5 Gbps
$66.00/mo
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
$0.00
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
$0.00
Pricing data last validated: . For current rates, check quake.ai/pricing.
Click to zoom
Harbor registry topology: private subnet, Harbor stack with data volume, one floating IP on HTTPS, Trivy scanner on push
Copy terraform.tfvars.example to terraform.tfvars and set:
HCL
key_name = "YOUR_KEY_NAME"
Leave domain commented out for a self-signed certificate on the floating IP. Defaults for flavor, Harbor version, and volume size are documented on the Harbor registry reference page.
From the template directory, run:
bash
tofu inittofu plantofu apply
Type yes when prompted. Provisioning takes several minutes while cloud-init installs Docker, generates the certificate and admin password, and starts the Harbor stack.
Run tofu destroy from the project directory when finished. Type yes to confirm. Remove the certificate you added on the client if you no longer need it: