Skip to content

Deploy the private network + VPN template with OpenTofu

Deployment · Updated Jun 2026

Coming from another cloud?

▸AWS·VPC VPN

This Quake AI feature maps to AWS’s VPC VPN.

▸Azure·Vnet VPN

This Quake AI feature maps to Azure’s Vnet VPN.

Deploy the private network + VPN template with OpenTofu

Stand up a WireGuard site-to-site VPN gateway on a private subnet using the validated OpenTofu template private-network-vpn. One floating IP terminates UDP traffic for the tunnel; cloud-init installs WireGuard and writes /etc/wireguard/wg0.conf.

Monthly cost estimate

Pricing calculator ↗

Sized as a custom package on shared vCPU.

Starting template$13.10/mo

Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.

What each resource is for

Gateway

s1a.small · 2 shared vCPU, 2 GiB RAM, 0.5 Gbps

$16.50/mo

Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.

Included in baseline

s1a.small

2 shared vCPU, 2 GiB RAM, 0.5 Gbps

$16.50

Compute + RAM rate basis

2 vCPU + 2 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.

—

Block storage (20 GiB)

20 GiB at $0.08/GiB/mo

$1.60

Public IP (included)

1 included with the custom package

$0.00

Package promotional discount

Flat −$5.00/mo on the custom package (same promotion as named plans).

$-5.00

Included at no charge

These line items are zero on Quake AI. Many other providers meter them separately.

Data transfer (inbound and outbound)

Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.

AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.

Learn more
$0.00

Private networking

Private networks, subnets, Neutron routers, and security groups are included with the plan.

VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.

$0.00

Control-plane API requests

OpenStack API calls for provisioning and management are included.

Some managed services on other clouds meter API calls or charge for premium control-plane features.

$0.00

Pricing data last validated: . For current rates, check quake.ai/pricing.

WireGuard peer192.168.99.0/24Quake AIFloating IPUDP 51820Private network10.0.0.0/24Routerto PublicStaticVPN gatewayWireGuard WireGuard tunnel
Click to zoom
Private network VPN topology: WireGuard gateway on a private subnet, one floating IP for UDP 51820, site-to-site tunnel to a remote peer

Prerequisites#

You need:

  • A Quake AI account with application credentials
  • OpenTofu 1.6.0 or later (installation guide)
  • OpenStack credentials sourced into the shell (source openrc.sh). See the OpenStack CLI guide.
  • An SSH key pair already uploaded to the project. See Add an SSH key.
  • A copy of the private-network-vpn template from the template reference page
  • Enough project quota for one s1a.small instance, one 20 GB boot volume, one router, one private network, and one floating IP
  • A WireGuard-capable peer outside Quake AI with a UDP path to your public IP on port 51820
  • wireguard-tools installed on the peer machine

Step 1: Generate a WireGuard key pair for your peer#

On the machine that acts as the remote peer, generate a key pair:

bash
umask 077
wg genkey | tee peer-private.key | wg pubkey > peer-public.key
cat peer-public.key

Save the public key for remote_wireguard_public_key. Record your peer public IP:

bash
curl -4 -s https://ifconfig.me

Use 192.168.99.0/24 on the peer side with address 192.168.99.2/32 after the tunnel is up.

Step 2: Configure variables and apply#

Copy terraform.tfvars.example to terraform.tfvars and set:

HCL
key_name                    = "YOUR_KEY_NAME"
remote_cidr                 = "192.168.99.0/24"
remote_endpoint             = "YOUR_PEER_PUBLIC_IP"
remote_wireguard_public_key = "YOUR_PEER_PUBLIC_KEY"

Defaults for private_cidr, vpn_port, and gateway flavor are documented on the Private Network + VPN reference page.

From the template directory, run:

bash
tofu init
tofu plan
tofu apply

Type yes when prompted. When the run finishes, note vpn_endpoint and gateway_private_ip from the outputs.

Step 3: Confirm WireGuard on the gateway#

SSH to the gateway through its floating IP and confirm cloud-init finished and WireGuard is running:

bash
GATEWAY_FIP=$(tofu output -raw vpn_endpoint | cut -d: -f1)
ssh -i ~/.ssh/YOUR_KEY -o StrictHostKeyChecking=accept-new ubuntu@"${GATEWAY_FIP}" 'cloud-init status --wait && sudo wg show wg0'

Copy the gateway public key:

bash
GATEWAY_WG_PUB=$(ssh -i ~/.ssh/YOUR_KEY ubuntu@"${GATEWAY_FIP}" 'sudo wg show wg0 public-key')
echo "${GATEWAY_WG_PUB}"

Step 4: Configure your peer and reach the gateway private IP#

On your workstation, create a WireGuard client configuration:

ini
[Interface]
PrivateKey = YOUR_PEER_PRIVATE_KEY
Address = 192.168.99.2/32

[Peer]
PublicKey = YOUR_GATEWAY_WG_PUBLIC_KEY
Endpoint = YOUR_GATEWAY_FIP:51820
AllowedIPs = 10.0.0.0/24
PersistentKeepalive = 25

Bring the interface up (Linux example):

bash
sudo cp peer-wg0.conf /etc/wireguard/wg0.conf
sudo wg-quick up wg0

From your workstation, ping the gateway private address through the tunnel:

bash
PRIVATE_IP=$(tofu output -raw gateway_private_ip)
ping -c 3 "${PRIVATE_IP}"

Successful replies confirm site-to-site routing through WireGuard.

When you finish testing, tear down the workstation interface:

bash
sudo wg-quick down wg0

Next steps#

Clean up#

Run tofu destroy from the project directory when finished. Bring down any local wg-quick interface you created.

Was this page helpful?