Skip to content
Deployments

Deploy Unleash with the unleash-feature-flags template

Deployment

Deploy Unleash with the unleash-feature-flags template

Stand up Unleash, an open-source feature-flags and experimentation platform, on a single Quake AI instance using the validated OpenTofu template unleash-feature-flags. You apply the template, log in and change the default admin password, create a project and a feature flag, connect a client SDK to read it, and put a domain in front for production use.

Unleash keeps your team's feature flags on infrastructure you own. You run it yourself; this is a self-hosted tool you operate, not a managed multi-tenant service.

Team memberApp using the SDKFloating IPUbuntu instanceCaddyreverse proxy (optional)UnleashappPostgreSQL proxies 443 to 4242flags + projectsHTTPS or :4242reads flag state
Click to zoom
What you'll build: an Unleash host on a single instance with a bundled PostgreSQL, reached directly on port 4242 or through an optional Caddy reverse proxy

Monthly cost estimate

Pricing calculator ↗

Sized as a custom package on shared vCPU.

Starting template$31.60/mo

Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.

What each resource is for

Unleash feature-flags host

s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps

Runs Unleash's app container alongside a bundled PostgreSQL, with the database data on an attached volume.

Unleash plus its bundled PostgreSQL runs on 4 vCPU and 4 GiB RAM. Size up for many concurrent SDK connections or a large flag inventory.

$33.00/mo

Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.

Included in baseline

s1a.medium

4 shared vCPU, 4 GiB RAM, 0.5 Gbps

$33.00

Compute + RAM rate basis

4 vCPU + 4 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.

—

Block storage (45 GiB)

45 GiB at $0.08/GiB/mo

$3.60

Public IP (included)

1 included with the custom package

$0.00

Package promotional discount

Flat −$5.00/mo on the custom package (same promotion as named plans).

$-5.00

Included at no charge

These line items are zero on Quake AI. Many other providers meter them separately.

Data transfer (inbound and outbound)

Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.

AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.

Learn more
$0.00

Private networking

Private networks, subnets, Neutron routers, and security groups are included with the plan.

VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.

$0.00

Control-plane API requests

OpenStack API calls for provisioning and management are included.

Some managed services on other clouds meter API calls or charge for premium control-plane features.

$0.00

Pricing data last validated: . For current rates, check quake.ai/pricing.

Prerequisites#

You need:

  • OpenTofu 1.6.0 or later (or Terraform 1.6.0 or later) installed locally.
  • Your OpenStack credentials sourced into the shell (source openrc.sh). See the OpenStack CLI guide.
  • An SSH keypair that already exists in your project. Record its name for the key_name variable.
  • A copy of the unleash-feature-flags template directory from the template reference page.
  • Node.js installed locally, to run the client SDK example in this walkthrough.

Step 1: Apply the template#

Copy the template's example variables file and set key_name:

bash
cp terraform.tfvars.example terraform.tfvars
HCL
key_name = "YOUR_KEY_NAME"

Initialize, preview, and apply:

bash
tofu init
tofu plan
tofu apply

OpenTofu provisions a private network, a router, a security group, a block volume mounted at /var/lib/docker, an instance, and a floating IP. On first boot, cloud-init installs Docker Engine, generates the PostgreSQL password into /opt/unleash/.env, and starts both postgres and unleash: no held-back service waits on manual configuration.

Read the outputs and record floating_ip and app_url:

bash
tofu output

Step 2: Log in and change the admin password#

  1. Open app_url from the previous step (http://YOUR_FLOATING_IP:4242). The raw app port is restricted to the private network by default; tunnel over SSH if you have not opened app_allowed_cidr to your workstation.
  2. Sign in with admin / unleash4all.
  3. Go to Admin settings > My profile > Change password and set a new password.

Step 3: Create a project and a feature flag#

  1. Select New project, name it (for example checkout-service), and create it.
  2. Inside the project, select New feature flag, name it new-checkout-flow, and set the flag type to Release.
  3. In the development environment, add a Standard strategy with a 50% gradual rollout, then toggle the environment on.

Step 4: Connect a client SDK#

From the Unleash admin UI, go to Admin settings > API access and generate a client API token scoped to your project and the development environment.

Install the Node.js SDK in a small test project:

bash
npm install unleash-client

Initialize the SDK and check the flag:

JavaScript
const { initialize, isEnabled } = require("unleash-client");

const unleash = initialize({
  url: "http://YOUR_FLOATING_IP:4242/api/",
  appName: "checkout-service",
  customHeaders: { Authorization: "YOUR_CLIENT_API_TOKEN" },
});

unleash.on("synchronized", () => {
  console.log("new-checkout-flow enabled:", isEnabled("new-checkout-flow"));
});

The SDK polls Unleash on an interval and caches flag state locally, so your application keeps working with the last known state if Unleash is briefly unreachable.

Step 5: Serve Unleash over HTTPS for production use#

Unleash has no auth-callback URL that blocks first boot, so this step is recommended for production use rather than required to get started.

  1. Create a DNS A record for your domain (for example flags.example.com) pointing at YOUR_FLOATING_IP. Follow How to point a domain at a Quake AI resource. Wait until it resolves:
bash
dig +short flags.example.com
  1. SSH to the instance and create /opt/unleash/Caddyfile:
flags.example.com {
  reverse_proxy 127.0.0.1:4242
}
  1. Add Caddy to /opt/unleash/docker-compose.yml:
YAML
services:
  caddy:
    image: caddy:2
    restart: unless-stopped
    network_mode: host
    volumes:
      - /opt/unleash/Caddyfile:/etc/caddy/Caddyfile
      - caddy_data:/data
volumes:
  caddy_data:

For background on certificates, see How to issue and auto-renew a TLS certificate with Let's Encrypt.

  1. Edit /opt/unleash/.env and set the public URL, then restart Unleash:
UNLEASH_URL=https://flags.example.com
bash
cd /opt/unleash
sudo docker compose up -d

UNLEASH_URL affects links in outgoing emails and integrations; it does not gate login or SDK access, so this step is safe to defer until you are ready to serve the app on a stable domain.

What you built#

  • Applied the unleash-feature-flags template to provision a network, security group, data volume, instance, and floating IP, with PostgreSQL and Unleash both started automatically by cloud-init
  • Changed the default admin password immediately after first login
  • Created a project and a feature flag with a gradual rollout strategy
  • Connected the Node.js client SDK to read the flag with a scoped API token
  • Served Unleash over HTTPS through an optional Caddy reverse proxy for production use

Scope of this deployment#

This template runs a single-VM Unleash host, not a managed feature-flags cloud. The instance is CPU-only and runs in one region, and it bundles PostgreSQL as a container on the same host. You operate the instance, Docker, Unleash, the database, and the data volume yourself: back them up, patch them, and snapshot the volume before you resize or rebuild. For a larger team, move PostgreSQL onto its own instance and size the app host up.

Next steps#

Clean up#

When you no longer need the deployment, destroy everything the template created:

bash
tofu destroy

Then remove the DNS A record you created in step 5, if you added one. Because Unleash and its database both live on the instance and its attached volume, tofu destroy removes them along with the infrastructure.

Before this
Was this page helpful?