Deploy the three-tier application template with OpenTofu
Deployment · Updated Jun 2026
Coming from another cloud?
▸AWS·3tier CF
This Quake AI feature maps to AWS’s 3tier CF.
▸Google Cloud·3tier Deployment Manager
This Quake AI feature maps to Google Cloud’s 3tier Deployment Manager.
Deploy the three-tier application template with OpenTofu
Stand up separate web, application, and database subnets on one private network using the validated OpenTofu templatethree-tier-app. The template provisions infrastructure and network isolation only; you configure each tier after apply with cloud-init, configuration management, or your own deployment pipeline.
Sized as a custom package on a mix of shared and dedicated vCPU.
Starting template$304.00/mo
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
2× Web tier
s1a.small · 2 shared vCPU, 2 GiB RAM, 0.5 Gbps
Serves incoming application traffic and terminates client connections.
Runs on shared CPU because the web tier scales horizontally. Add instances with web_count rather than a larger flavor.
$33.00/mo
2× App tier
m2a.large · 2 dedicated vCPU, 8 GiB RAM, 0.5 Gbps
Runs the application logic the web tier calls, on a private subnet with no public IP.
Uses general-purpose dedicated CPU for steady request handling.
$132.00/mo
Database
m2a.xlarge · 4 dedicated vCPU, 16 GiB RAM, 1 Gbps
Runs the database on a private subnet, with a dedicated data volume per instance.
Uses a memory-optimized flavor so the working set stays in RAM.
$132.00/mo
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
$0.00
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
$0.00
Dev/test vs production
Start on shared CPU for dev/test, then promote to dedicated for production with a flavor resize. The network, storage, and template stay the same.
Dev/test on shared CPU
Burstable s1a flavors; suited to prototyping and low or bursty load.
$106.00/mo
Production on the configured CPU
The headline estimate above; predictable steady-load performance.
$304.00/mo
Saves $198.00/mo while you build on shared CPU.
Shared flavors carry less RAM (m2a.large (8 GiB RAM) -> s1a.small (2 GiB RAM); m2a.xlarge (16 GiB RAM) -> s1a.medium (4 GiB RAM)). A resize reboots the instance; data on attached volumes persists. Size the dedicated flavor for the RAM your production workload needs.
Pricing data last validated: . For current rates, check quake.ai/pricing.
Click to zoom
Three-tier topology: web, app, and database subnets with one floating IP on the first web instance
Copy terraform.tfvars.example to terraform.tfvars and set:
HCL
key_name = "YOUR_KEY_NAME"
Defaults for tier counts, flavors, and subnet CIDRs are documented on the Three-Tier Application reference page. Override counts or flavors in terraform.tfvars if your project quota is tight.
Type yes when prompted. At the default counts, OpenTofu creates five instances, three subnets, tier-specific security groups, and one floating IP on the first web port.
When the run finishes, run tofu output and note web_floating_ip and the private IP lists for each tier.
Step 3: Verify subnet isolation and web-tier reachability#
List the instances and their network attachments:
bash
openstack server list --name three-tier-app -c Name -c Networks -c Status
Confirm the floating IP is bound to the first web port:
bash
openstack floating ip list --floating-ip-address "$(tofu output -raw web_floating_ip)" -c "Floating IP Address" -c Port -c "Fixed IP Address"
The Fixed IP Address column should match the first address in tofu output -json web_ips.
Test that the web tier accepts inbound traffic on the public entrypoint:
Run tofu destroy from the project directory when finished. Type yes to confirm. Verify in the Console that all instances, data volumes, and the floating IP are gone.