Skip to content

Self-hosted OIDC identity provider (Keycloak)

Template

Self-hosted OIDC identity provider (Keycloak)

This pattern composes Compute, Network, and Block Storage into a self-hosted identity provider you run on infrastructure you control.

What this template does#

Provisions a single instance running Keycloak, an open-source identity and access management server (a self-hosted alternative to Clerk or Auth0). Your application authenticates against realms and clients you own:

  • Compute instance that runs Keycloak in Docker alongside a bundled PostgreSQL (4 vCPU and 4 GiB RAM)
  • Private network, subnet, router, port, and security group; a floating IP for public access
  • A block volume mounted at /var/lib/docker, so the realm, client, and user data lives on a volume you can grow rather than on the boot disk
  • cloud-init installs Docker Engine and brings up Keycloak in start-dev bootstrap mode against the bundled PostgreSQL

The bootstrap admin password and the database password are generated on first boot and written to /opt/auth-oidc/.env; no credential ships with this template.

Keycloak's HTTPS-before-real-login requirement#

Keycloak's production start command refuses to issue real tokens over plain HTTP: it expects a certificate on the server itself, or KC_HTTP_ENABLED=true plus KC_PROXY_HEADERS=xforwarded when a reverse proxy terminates TLS in front of it. This template starts in start-dev bootstrap mode, which tolerates plain HTTP so you can create your first realm and client without a domain in hand yet. The bootstrap server is gated to app_allowed_cidr (the private network by default); it is not the path real users sign in through. Switch to start with a domain and a reverse proxy before pointing a real application at this identity provider.

Why Keycloak over Authentik#

This template leads with Keycloak because it is the most widely deployed open-source identity server, has the longest track record in enterprise and Kubernetes environments, and its realm/client model maps directly onto the OIDC concepts most application frameworks already expect. Authentik is a reasonable alternative if you want a more opinionated, modern admin UI and do not need Keycloak's broader protocol surface (SAML, Kerberos brokering, fine-grained authorization services).

Parameters#

ParameterDescriptionDefault
key_nameSSH keypair name (must already exist)No default
flavor_nameInstance size (Keycloak plus PostgreSQL runs on 4 vCPU / 4 GiB)s1a.medium
image_nameOperating system imageUbuntu-24.04
app_nameDisplay name prefix for resourcesauth-oidc
volume_sizeBlock volume size in GiB, mounted at /var/lib/docker20
external_networkExternal network for floating IP allocationPublicStatic
private_cidrCIDR for the private subnet10.48.0.0/24
app_allowed_cidrCIDR allowed to reach Keycloak on port 808010.48.0.0/24

Finish setup after apply#

cloud-init starts Keycloak in start-dev mode against the bundled PostgreSQL and writes the generated secrets to /opt/auth-oidc/.env. Read the bootstrap admin password over SSH:

bash
sudo grep KC_BOOTSTRAP_ADMIN_PASSWORD /opt/auth-oidc/.env

Sign in to the admin console at http://YOUR_FLOATING_IP:8080, create a realm and a client, and register your application's redirect URIs. When you are ready for real traffic, move to production:

  1. Point a domain's DNS A record at the floating IP and put a reverse proxy (Caddy or Nginx) in front for HTTPS on 443.
  2. Edit /opt/auth-oidc/.env: set KC_HOSTNAME to your public HTTPS address, KC_PROXY_HEADERS=xforwarded, and KC_HTTP_ENABLED=true.
  3. Change the keycloak service's command in /opt/auth-oidc/docker-compose.yml from start-dev to start, then run sudo docker compose up -d.

Access and security#

Keycloak listens on port 8080 over plain HTTP in bootstrap mode. The security group restricts 8080 to app_allowed_cidr, which defaults to the private network only. Ports 80 and 443 stay open for the reverse proxy you add before going to production; they carry no traffic until then.

When to use this pattern#

Run a self-hosted OIDC identity provider for one or more applications on a host you operate. Keycloak suits a team that wants realms, clients, and social-login brokering without a per-monthly-active-user SaaS bill. The bundled PostgreSQL suits a single identity provider; to run it separately, point KC_DB_URL at a self-managed PostgreSQL instance.

Estimated cost#

Monthly cost estimate

Pricing calculator ↗

Sized as a custom package on shared vCPU.

Starting template$32.00/mo

Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.

What each resource is for

Keycloak identity-provider host

s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps

Runs Keycloak in Docker (the self-hosted OIDC identity provider) alongside its bundled PostgreSQL, with the realm and client data on an attached volume.

Keycloak plus its bundled PostgreSQL runs on 4 vCPU and 4 GiB RAM. Size up for many realms or high token-issuance volume.

$33.00/mo

Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.

Included in baseline

s1a.medium

4 shared vCPU, 4 GiB RAM, 0.5 Gbps

$33.00

Compute + RAM rate basis

4 vCPU + 4 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.

—

Block storage (50 GiB)

50 GiB at $0.08/GiB/mo

$4.00

Public IP (included)

1 included with the custom package

$0.00

Package promotional discount

Flat −$5.00/mo on the custom package (same promotion as named plans).

$-5.00

Included at no charge

These line items are zero on Quake AI. Many other providers meter them separately.

Data transfer (inbound and outbound)

Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.

AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.

Learn more
$0.00

Private networking

Private networks, subnets, Neutron routers, and security groups are included with the plan.

VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.

$0.00

Control-plane API requests

OpenStack API calls for provisioning and management are included.

Some managed services on other clouds meter API calls or charge for premium control-plane features.

$0.00

Pricing data last validated: . For current rates, check quake.ai/pricing.

Template source#

7 files. Download the zip or expand to copy any file.Download auth-oidc.zip
Show source (7 files)
main.tfHCL
data "openstack_images_image_v2" "os" {
  name        = var.image_name
  most_recent = true
}

data "openstack_networking_network_v2" "external" {
  name = var.external_network
}

resource "openstack_networking_network_v2" "private" {
  name           = "${var.app_name}-net"
  admin_state_up = true
}

resource "openstack_networking_subnet_v2" "private" {
  name            = "${var.app_name}-subnet"
  network_id      = openstack_networking_network_v2.private.id
  cidr            = var.private_cidr
  ip_version      = 4
  dns_nameservers = ["1.1.1.1", "8.8.8.8"]
}

resource "openstack_networking_router_v2" "main" {
  name                = "${var.app_name}-router"
  external_network_id = data.openstack_networking_network_v2.external.id
}

resource "openstack_networking_router_interface_v2" "private" {
  router_id = openstack_networking_router_v2.main.id
  subnet_id = openstack_networking_subnet_v2.private.id
}

resource "openstack_networking_secgroup_v2" "auth_oidc" {
  name        = "${var.app_name}-sg"
  description = "SSH and HTTP/HTTPS for a reverse proxy; admin console port 8080 restricted"
}

resource "openstack_networking_secgroup_rule_v2" "ssh" {
  direction         = "ingress"
  ethertype         = "IPv4"
  protocol          = "tcp"
  port_range_min    = 22
  port_range_max    = 22
  remote_ip_prefix  = "0.0.0.0/0"
  security_group_id = openstack_networking_secgroup_v2.auth_oidc.id
}

# 80 and 443 carry Keycloak in production mode, served over HTTPS through a
# reverse proxy (Caddy or Nginx). Keycloak's production "start" command refuses
# to issue real tokens over plain HTTP, so the domain path is the expected way
# real users reach it; see the reference page.
resource "openstack_networking_secgroup_rule_v2" "http" {
  direction         = "ingress"
  ethertype         = "IPv4"
  protocol          = "tcp"
  port_range_min    = 80
  port_range_max    = 80
  remote_ip_prefix  = "0.0.0.0/0"
  security_group_id = openstack_networking_secgroup_v2.auth_oidc.id
}

resource "openstack_networking_secgroup_rule_v2" "https" {
  direction         = "ingress"
  ethertype         = "IPv4"
  protocol          = "tcp"
  port_range_min    = 443
  port_range_max    = 443
  remote_ip_prefix  = "0.0.0.0/0"
  security_group_id = openstack_networking_secgroup_v2.auth_oidc.id
}

# Raw Keycloak HTTP on 8080 is restricted to app_allowed_cidr (the private
# network by default). Use it for the initial start-dev realm/client setup
# over an SSH tunnel or a scoped workstation IP; put a reverse proxy on 443 in
# front, and switch Keycloak to production mode, before real users sign in.
resource "openstack_networking_secgroup_rule_v2" "app" {
  direction         = "ingress"
  ethertype         = "IPv4"
  protocol          = "tcp"
  port_range_min    = 8080
  port_range_max    = 8080
  remote_ip_prefix  = var.app_allowed_cidr
  security_group_id = openstack_networking_secgroup_v2.auth_oidc.id
}

resource "openstack_networking_port_v2" "auth_oidc" {
  name               = "${var.app_name}-port"
  network_id         = openstack_networking_network_v2.private.id
  security_group_ids = [openstack_networking_secgroup_v2.auth_oidc.id]

  fixed_ip {
    subnet_id = openstack_networking_subnet_v2.private.id
  }

  depends_on = [openstack_networking_router_interface_v2.private]
}

resource "openstack_blockstorage_volume_v3" "data" {
  name = "${var.app_name}-data"
  size = var.volume_size
}

resource "openstack_compute_instance_v2" "auth_oidc" {
  name        = var.app_name
  flavor_name = var.flavor_name
  key_pair    = var.key_name

  user_data = templatefile("${path.module}/cloud-init/auth-oidc.yaml.tftpl", {
    app_name = var.app_name
  })

  block_device {
    uuid                  = data.openstack_images_image_v2.os.id
    source_type           = "image"
    destination_type      = "volume"
    volume_size           = 30
    boot_index            = 0
    delete_on_termination = true
  }

  network {
    port = openstack_networking_port_v2.auth_oidc.id
  }
}

resource "openstack_compute_volume_attach_v2" "data" {
  instance_id = openstack_compute_instance_v2.auth_oidc.id
  volume_id   = openstack_blockstorage_volume_v3.data.id
}

resource "openstack_networking_floatingip_v2" "auth_oidc" {
  pool = var.external_network
}

resource "openstack_networking_floatingip_associate_v2" "auth_oidc" {
  floating_ip = openstack_networking_floatingip_v2.auth_oidc.address
  port_id     = openstack_networking_port_v2.auth_oidc.id
}
variables.tfHCL
variable "key_name" {
  description = "SSH keypair name (must already exist in your project)"
  type        = string
}

variable "flavor_name" {
  description = "Instance size. Keycloak plus its bundled PostgreSQL runs comfortably on 4 vCPU and 4 GiB RAM (s1a.medium); the JVM-based server wants headroom beyond what a smaller flavor gives it. Size up for many realms or high token-issuance volume."
  type        = string
  default     = "s1a.medium"
}

variable "image_name" {
  description = "Operating system image. Ubuntu 24.04 is the recommended base."
  type        = string
  default     = "Ubuntu-24.04"
}

variable "app_name" {
  description = "Display name prefix for compute and network resources"
  type        = string
  default     = "auth-oidc"
}

variable "volume_size" {
  description = "Block volume size in GiB, mounted at /var/lib/docker so the identity-provider data (the PostgreSQL database holding realms, clients, and users) lives on a volume you can grow rather than on the boot disk."
  type        = number
  default     = 20
}

variable "external_network" {
  description = "Shared external network for router gateway and floating IPs; defaults to PublicStatic (persisted FIP / production pattern). Override with PublicEphemeral for ephemeral demos."
  type        = string
  default     = "PublicStatic"
}

variable "private_cidr" {
  description = "CIDR for the private tenant network the instance lives in"
  type        = string
  default     = "10.48.0.0/24"
}

variable "app_allowed_cidr" {
  description = "CIDR allowed to reach Keycloak on port 8080. Defaults to the private network only, so the admin console and the start-dev bootstrap are not exposed to the public internet on the raw port. Keycloak's production mode (start) refuses to serve real login traffic without HTTPS, so the normal access path is a domain with TLS on 443 behind a reverse proxy; reach port 8080 directly only for initial realm and client setup, over an SSH tunnel or from this CIDR. To reach it from your workstation during setup, set this to YOUR_IP/32."
  type        = string
  default     = "10.48.0.0/24"
}
outputs.tfHCL
output "instance_id" {
  description = "ID of the compute instance running Keycloak"
  value       = openstack_compute_instance_v2.auth_oidc.id
}

output "floating_ip" {
  description = "Public floating IP address of the Keycloak host"
  value       = openstack_networking_floatingip_v2.auth_oidc.address
}

output "private_ip" {
  description = "Private IP address of the instance"
  value       = openstack_compute_instance_v2.auth_oidc.access_ip_v4
}

output "admin_console_url" {
  description = "Keycloak admin console URL on port 8080, reachable from app_allowed_cidr (the private network by default) while the server runs in start-dev bootstrap mode. Switch to production mode behind a reverse proxy with HTTPS before pointing real applications at this identity provider."
  value       = "http://${openstack_networking_floatingip_v2.auth_oidc.address}:8080"
}
versions.tfHCL
terraform {
  required_version = ">= 1.6.0"

  required_providers {
    openstack = {
      source  = "terraform-provider-openstack/openstack"
      version = "~> 2.0"
    }
  }
}

provider "openstack" {}
terraform.tfvars.exampleHCL
# Required: SSH keypair must already exist in your project
key_name = "YOUR_KEY_NAME"

# Recommended: restrict the admin console (8080) to your workstation IP for
# the initial realm and client setup. Leave unset to keep 8080 reachable only
# from the private network and tunnel over SSH. Keycloak's production mode
# refuses real login traffic without HTTPS, so the normal access path for real
# users is a domain with HTTPS on 443 behind a reverse proxy.
# app_allowed_cidr = "203.0.113.10/32"

# flavor_name = "s1a.medium"
# image_name = "Ubuntu-24.04"
# app_name = "auth-oidc"
# volume_size = 20
# external_network = "PublicStatic"
# private_cidr = "10.48.0.0/24"
cloud-init/auth-oidc.yaml.tftpl
#cloud-config
package_update: true
packages:
  - ca-certificates
  - curl
write_files:
  - path: /opt/auth-oidc/docker-compose.yml
    permissions: "0644"
    content: |
      # Keycloak identity provider for ${app_name}. The admin console and the
      # OIDC endpoints listen on port 8080. cloud-init starts Keycloak in
      # start-dev mode against the bundled PostgreSQL so you can create a
      # realm and a client right away from app_allowed_cidr; Keycloak's
      # production "start" command refuses to issue real tokens over plain
      # HTTP, so switch to it (with KC_HOSTNAME, KC_PROXY_HEADERS, and
      # KC_HTTP_ENABLED) once a domain and a reverse proxy are in front. No
      # credential ships with this template: the bootstrap admin password and
      # the database password are generated on first boot.
      services:
        keycloak:
          image: quay.io/keycloak/keycloak:26.6.4
          restart: unless-stopped
          command: start-dev
          ports:
            - "8080:8080"
          env_file:
            - /opt/auth-oidc/.env
          depends_on:
            - postgres
        postgres:
          image: postgres:16-alpine
          restart: unless-stopped
          env_file:
            - /opt/auth-oidc/.env
          volumes:
            - auth_oidc_pg:/var/lib/postgresql/data
      volumes:
        auth_oidc_pg:
runcmd:
  - |
    set -e
    # The data volume attaches as /dev/sdb on this platform (not /dev/vdb).
    # Mount it at /var/lib/docker before Docker is installed so the
    # PostgreSQL data (realms, clients, and users) lives on the resizable
    # volume rather than the boot disk.
    DEV=/dev/sdb
    for i in $(seq 1 30); do [ -b "$DEV" ] && break; sleep 5; done
    if ! blkid "$DEV" >/dev/null 2>&1; then mkfs.ext4 -F -L authoidcdata "$DEV"; fi
    mkdir -p /var/lib/docker
    mount "$DEV" /var/lib/docker
    grep -q "$DEV" /etc/fstab || echo "$DEV /var/lib/docker ext4 defaults,nofail 0 2" >> /etc/fstab
    # Install Docker Engine plus the compose plugin from Docker's convenience
    # script.
    curl -fsSL https://get.docker.com | sh
    # Generate the bootstrap admin password and the bundled database password
    # on first boot. These never leave this instance.
    ADMIN_PASS=$(openssl rand -hex 16)
    PGPASS=$(openssl rand -hex 24)
    umask 077
    {
      echo "POSTGRES_USER=keycloak"
      echo "POSTGRES_PASSWORD=$PGPASS"
      echo "POSTGRES_DB=keycloak"
      echo "KC_DB=postgres"
      echo "KC_DB_URL=jdbc:postgresql://postgres:5432/keycloak"
      echo "KC_DB_USERNAME=keycloak"
      echo "KC_DB_PASSWORD=$PGPASS"
      echo "KC_BOOTSTRAP_ADMIN_USERNAME=admin"
      echo "KC_BOOTSTRAP_ADMIN_PASSWORD=$ADMIN_PASS"
      echo "# Set these and switch the compose command to 'start' before"
      echo "# pointing real applications at this identity provider:"
      echo "# KC_HOSTNAME=https://auth.example.com"
      echo "# KC_PROXY_HEADERS=xforwarded"
      echo "# KC_HTTP_ENABLED=true"
    } > /opt/auth-oidc/.env
    chmod 600 /opt/auth-oidc/.env
    cat <<'CREDS' > /opt/auth-oidc/INITIAL_ADMIN_PASSWORD.txt
    The bootstrap admin password is in /opt/auth-oidc/.env as
    KC_BOOTSTRAP_ADMIN_PASSWORD. Read it, then delete this file:
      sudo cat /opt/auth-oidc/.env | grep KC_BOOTSTRAP_ADMIN_PASSWORD
      sudo shred -u /opt/auth-oidc/INITIAL_ADMIN_PASSWORD.txt
    CREDS
    chmod 600 /opt/auth-oidc/INITIAL_ADMIN_PASSWORD.txt
    cd /opt/auth-oidc
    docker compose up -d
README.mdMarkdown
# Self-hosted OIDC identity provider (Keycloak)

Single compute instance running [Keycloak](https://www.keycloak.org), an open-source identity and access management server (a self-hosted alternative to Clerk or Auth0) on infrastructure you control. After apply, you create a realm and a client, register your application's redirect URIs, point a domain and a reverse proxy at the host, switch Keycloak to production mode, and wire your application to the realm's OIDC endpoints.


**Network class:** production — `external_network` defaults to `PublicStatic` for persisted floating IPs and multi-tier stacks; override with `PublicEphemeral` for ephemeral demos.

The instance provisions a private network, a floating IP, and a block volume mounted at `/var/lib/docker` so the realm and client data lives on a resizable volume. cloud-init installs Docker Engine and brings up Keycloak in `start-dev` bootstrap mode against a bundled PostgreSQL database.

## Where this fits

Keycloak is the identity layer behind any application that needs sign-in: OIDC and SAML, social login brokering, multi-factor authentication, and per-application clients, all on infrastructure you own rather than a metered SaaS. It is the self-hosted equivalent of Clerk or Auth0 in the [self-hosted vibecode stack](/resources/solutions/self-hosted-vibecode-stack).

## Why Keycloak over Authentik

Both are credible self-hosted OIDC providers. This template leads with Keycloak because it is the most widely deployed open-source identity server, has the longest track record in enterprise and Kubernetes environments, and its realm/client model maps directly onto the OIDC concepts most application frameworks already expect. [Authentik](https://goauthentik.io) is a reasonable alternative if you want a more opinionated, modern admin UI and do not need Keycloak's broader protocol surface (SAML, Kerberos brokering, fine-grained authorization services).

## Keycloak's HTTPS-before-real-login requirement

Keycloak's production `start` command refuses to issue real tokens over plain HTTP: it expects either a TLS certificate configured on the server itself, or `KC_HTTP_ENABLED=true` plus `KC_PROXY_HEADERS=xforwarded` when a reverse proxy terminates TLS in front of it. This template starts Keycloak in `start-dev` bootstrap mode instead, which tolerates plain HTTP so you can create your first realm and client without a domain in hand. The admin console and the `start-dev` server are gated to `app_allowed_cidr` (the private network by default); they are not the path real users sign in through. Switch to `start` with a domain and a reverse proxy before pointing a real application at this identity provider.

## Prerequisites

- OpenTofu >= 1.6.0 or Terraform >= 1.6.0
- Quake AI account with OpenStack credentials
- An existing SSH keypair in your project (the value of `key_name` must match that keypair)
- A domain you can point at the instance once you move off `start-dev`

## Resource baseline

Keycloak plus its bundled PostgreSQL runs on 4 vCPU and 4 GiB RAM. The default `s1a.medium` flavor leaves headroom for the JVM-based server. Size up for many realms or high token-issuance volume.

## Usage

1. Clone or copy this template directory
2. Copy `terraform.tfvars.example` to `terraform.tfvars` and fill in your values
3. Source your OpenStack credentials: `source openrc.sh`
4. Initialize: `tofu init`
5. Preview: `tofu plan`
6. Apply: `tofu apply`

After apply, cloud-init installs Docker, generates the bootstrap admin password and the database password into `/opt/auth-oidc/.env`, and starts Keycloak in `start-dev` mode. Read the bootstrap admin password over SSH:

```bash
sudo grep KC_BOOTSTRAP_ADMIN_PASSWORD /opt/auth-oidc/.env
```

No credential ships with this template: the bootstrap admin password and the database password are generated on first boot.

## Access and security

Keycloak listens on port 8080 over plain HTTP in bootstrap mode. The security group restricts 8080 to `app_allowed_cidr`, which defaults to the private network only. Ports 80 and 443 stay open for the reverse proxy you add before going to production; they carry no traffic until then.

## Moving to production

1. Point a domain's DNS A record at `floating_ip` and put a reverse proxy (Caddy or Nginx) in front for HTTPS on 443.
2. Edit `/opt/auth-oidc/.env`: uncomment and set `KC_HOSTNAME` to your public HTTPS address, `KC_PROXY_HEADERS=xforwarded`, and `KC_HTTP_ENABLED=true`.
3. Change the `keycloak` service's `command` in `/opt/auth-oidc/docker-compose.yml` from `start-dev` to `start`, then restart:

```bash
cd /opt/auth-oidc
sudo docker compose up -d
```

## Datastores

This template bundles PostgreSQL as a container on the same instance, which suits a single identity provider. To run it as a separate service, point `KC_DB_URL` in `/opt/auth-oidc/.env` at a [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres) instance and remove the bundled `postgres` service from the compose file.

## Variables

| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `key_name` | string | yes | n/a | SSH keypair name (must already exist in your project) |
| `flavor_name` | string | no | `s1a.medium` | Instance size (Keycloak plus PostgreSQL runs on 4 vCPU / 4 GiB) |
| `image_name` | string | no | `Ubuntu-24.04` | Operating system image |
| `app_name` | string | no | `auth-oidc` | Display name prefix for resources |
| `volume_size` | number | no | `20` | Block volume size in GiB, mounted at `/var/lib/docker` |
| `external_network` | string | no | `PublicStatic` | Persisted FIP / production default; override with `PublicEphemeral` for demos |
| `private_cidr` | string | no | `10.48.0.0/24` | CIDR for the private subnet |
| `app_allowed_cidr` | string | no | `10.48.0.0/24` | CIDR allowed to reach Keycloak on port 8080 |

## Outputs

| Name | Description |
| --- | --- |
| `floating_ip` | Public floating IP assigned to the instance |
| `private_ip` | Private IP address of the instance |
| `admin_console_url` | Keycloak admin console URL on port 8080 (bootstrap mode only) |
| `instance_id` | Compute instance ID |

## Scope

This is a single-VM Keycloak host that you operate, not a managed identity cloud. It is CPU-only and runs in one region. You operate the instance, Docker, Keycloak, PostgreSQL, and the data volume yourself: back them up, patch them, and watch resource use as you add realms and clients. For larger deployments, move PostgreSQL onto its own instance and run Keycloak in clustered mode, which this template does not set up.

## Documentation

See also: [self-managed PostgreSQL](/resources/iac-templates/self-managed-postgres), [Outline](/resources/iac-templates/outline-docs) (an existing OIDC consumer example)
Resources, parameters, and variables
Provisions
Parameterized by
Variables
  • key_namerequired
  • flavor_name="s1a.medium"
  • image_name="Ubuntu-24.04"
  • app_name="auth-oidc"
  • volume_size=20
  • external_network="PublicStatic"
  • private_cidr="10.48.0.0/24"
  • app_allowed_cidr="10.48.0.0/24"

Customize this pattern#

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

For the full policy, see Usage Guidelines.

Was this page helpful?