Skip to content
Deployments

Deploy Infisical with the infisical-secrets template

Deployment

Deploy Infisical with the infisical-secrets template

Stand up Infisical, an open-source secrets-management platform, on a single Quake AI instance using the validated OpenTofu template infisical-secrets. You apply the template, point a domain at the host and serve it over HTTPS, set the public URL and start the app, sign up the first admin account, create a project and a secret, and pull it with the Infisical CLI.

Infisical keeps your team's secrets on infrastructure you own. You run it yourself; this is a self-hosted tool you operate, not a managed service.

Team memberFloating IPUbuntu instanceCaddyreverse proxyInfisicalappPostgreSQLRedis proxies 443 to 8080secrets (encrypted)jobs + cacheHTTPS
Click to zoom
What you'll build: an Infisical host on a single instance with bundled PostgreSQL and Redis, reached over HTTPS through a Caddy reverse proxy

Monthly cost estimate

Pricing calculator ↗

Sized as a custom package on shared vCPU.

Starting template$32.00/mo

Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.

What each resource is for

Infisical secrets-management host

s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps

Runs Infisical in Docker (the secrets-management app) alongside its bundled PostgreSQL and Redis, with the database and Redis data on an attached volume.

Infisical plus its bundled PostgreSQL and Redis runs on 4 vCPU and 4 GiB RAM. Size up for large teams or heavy secret-access volume.

$33.00/mo

Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.

Included in baseline

s1a.medium

4 shared vCPU, 4 GiB RAM, 0.5 Gbps

$33.00

Compute + RAM rate basis

4 vCPU + 4 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.

—

Block storage (50 GiB)

50 GiB at $0.08/GiB/mo

$4.00

Public IP (included)

1 included with the custom package

$0.00

Package promotional discount

Flat −$5.00/mo on the custom package (same promotion as named plans).

$-5.00

Included at no charge

These line items are zero on Quake AI. Many other providers meter them separately.

Data transfer (inbound and outbound)

Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.

AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.

Learn more
$0.00

Private networking

Private networks, subnets, Neutron routers, and security groups are included with the plan.

VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.

$0.00

Control-plane API requests

OpenStack API calls for provisioning and management are included.

Some managed services on other clouds meter API calls or charge for premium control-plane features.

$0.00

Pricing data last validated: . For current rates, check quake.ai/pricing.

Prerequisites#

You need:

  • OpenTofu 1.6.0 or later (or Terraform 1.6.0 or later) installed locally.
  • Your OpenStack credentials sourced into the shell (source openrc.sh). See the OpenStack CLI guide.
  • An SSH keypair that already exists in your project. Record its name for the key_name variable.
  • A copy of the infisical-secrets template directory from the template reference page.
  • A domain you can point at the instance. Infisical needs a stable public URL for auth callbacks and CLI/SDK access.
  • The Infisical CLI installed locally, to pull the secret you create in this walkthrough.

Step 1: Apply the template#

Copy the template's example variables file and set key_name:

bash
cp terraform.tfvars.example terraform.tfvars
HCL
key_name = "YOUR_KEY_NAME"

Initialize, preview, and apply:

bash
tofu init
tofu plan
tofu apply

OpenTofu provisions a private network, a router, a security group, a block volume mounted at /var/lib/docker, an instance, and a floating IP. On first boot, cloud-init installs Docker Engine, generates ENCRYPTION_KEY, AUTH_SECRET, and the database password into /opt/infisical/.env, and starts PostgreSQL and Redis. Infisical itself starts after you finish configuration in the next steps.

Read the outputs and record floating_ip and app_url:

bash
tofu output

Step 2: Point a domain at the host and serve HTTPS with Caddy#

Infisical builds absolute links and auth callbacks from its public URL, so it needs a domain with TLS before you sign up your first account.

  1. Create a DNS A record for your domain (for example secrets.example.com) pointing at YOUR_FLOATING_IP. Follow How to point a domain at a Quake AI resource. Wait until it resolves:
bash
dig +short secrets.example.com
  1. SSH to the instance and create /opt/infisical/Caddyfile:
secrets.example.com {
  reverse_proxy 127.0.0.1:8080
}
  1. Add Caddy to /opt/infisical/docker-compose.yml:
YAML
services:
  caddy:
    image: caddy:2
    restart: unless-stopped
    network_mode: host
    volumes:
      - /opt/infisical/Caddyfile:/etc/caddy/Caddyfile
      - caddy_data:/data
volumes:
  caddy_data:

For background on certificates, see How to issue and auto-renew a TLS certificate with Let's Encrypt.

Step 3: Set SITE_URL and start Infisical#

Edit /opt/infisical/.env on the instance and set the public URL:

SITE_URL=https://secrets.example.com

Start the app:

bash
cd /opt/infisical
sudo docker compose up -d
sudo docker compose ps

The infisical container joins the running PostgreSQL and Redis. Confirm it reports healthy.

Step 4: Sign up and create your first project#

  1. Open https://secrets.example.com. Infisical has built-in email-and-password login, so you sign up directly: no external identity provider to configure first. The first account to sign up becomes the organization admin.
  2. Create a project (for example payments-service). Infisical scaffolds dev, staging, and prod environments for the project.
  3. Inside the dev environment, select Add secret, set the key to STRIPE_API_KEY, and give it a placeholder value. Infisical encrypts the value before it reaches PostgreSQL.

Step 5: Pull the secret with the Infisical CLI#

From your workstation, point the CLI at your self-hosted instance and authenticate:

bash
export INFISICAL_DOMAIN="https://secrets.example.com"
infisical login

Initialize the project link in a local working directory, then list the secret you created:

bash
infisical init
infisical secrets --env=dev

Run a local command with the secret injected as an environment variable, without ever writing it to a file:

bash
infisical run --env=dev -- printenv STRIPE_API_KEY

Step 6: Invite a teammate#

  1. Go to Organization Settings > Members > Invite member.
  2. Enter a teammate's email. Infisical sends an invite they accept with their own email and password (or you configure SSO later, separately from the steps above).
  3. Add them to the payments-service project with a role scoped to the environments they need.

What you built#

  • Applied the infisical-secrets template to provision a network, security group, data volume, instance, and floating IP, with PostgreSQL and Redis started by cloud-init
  • Served Infisical over HTTPS by pointing a domain at the floating IP and routing it through a Caddy reverse proxy
  • Signed up the first admin account using Infisical's built-in login
  • Created a project, an environment, and a secret, then pulled it with the Infisical CLI
  • Backed up ENCRYPTION_KEY before storing any real secrets
  • Invited a teammate

Scope of this deployment#

This template runs a single-VM Infisical host, not a managed secrets cloud. The instance is CPU-only and runs in one region, and it bundles PostgreSQL and Redis as containers on the same host. You operate the instance, Docker, Infisical, the database, Redis, and the data volume yourself: back them up (ENCRYPTION_KEY especially), patch them, and snapshot the volume before you resize or rebuild. For a larger team, move PostgreSQL and Redis onto their own instances and size the app host up.

Next steps#

Clean up#

When you no longer need the deployment, destroy everything the template created:

bash
tofu destroy

Then remove the DNS A record you created in step 2. Because Infisical, its database, and Redis all live on the instance and its attached volume, tofu destroy removes them along with the infrastructure. Export the secrets you want to keep first; the Infisical CLI's infisical export command writes a project's secrets to a local file in dotenv or YAML format.

Before this
Was this page helpful?