CI/CD pipelines
CI/CD pipelines
Run a complete build-and-deploy pipeline on Quake AI infrastructure you operate: a git forge, a CI runner, a container registry, and a deploy target. You bring the repositories, workflows, and deploy steps; Quake AI provides the Compute, Network, and storage the pipeline runs on.
What this is for#
Teams that want the whole loop from commit to running workload on infrastructure they control, rather than split across third-party SaaS, run each stage on Quake AI Compute. A push to a self-hosted Forgejo forge triggers a workflow on its bundled Actions runner; the runner builds a container image and pushes it to a self-hosted Harbor registry; a deploy step pulls the image onto a VM or into a Kubernetes cluster. The outcome is a pipeline assembled from validated OpenTofu templates and their companion tutorials, with workflow files that match the GitHub Actions syntax your team already knows.
This page threads the components into one flow. For the IaC and migration side of DevOps (OpenTofu and Heat estates, remote state, moving an existing pipeline from a hyperscaler), see DevOps automation and CI/CD.
Reference architecture#
Download diagram: SVG, PNG, and PDF.
The pipeline runs as four stages, each on Compute you operate:
-
Source. Developers push to a git forge. A self-hosted Forgejo forge keeps repositories on a VM you control, with the same workflow syntax as GitHub Actions. A hosted GitHub or GitLab repository works too when you register a runner against it.
-
Build. A push triggers a workflow on a runner. The Forgejo template bundles one Actions runner that builds container images in Docker; the CI runner tutorial covers a standalone runner you point at any forge. Runners are AMD EPYC Compute instances sized for the build, not for inference.
-
Registry. The runner pushes the built image to a registry. A self-hosted Harbor registry stores Docker and OCI images over HTTPS with projects, role-based access, and image scanning. Authentication is required for push and pull; there is no anonymous write.
-
Deploy. A deploy step pulls the image and runs it. Targets include a VM over SSH, the Coolify host for push-to-deploy, or a Kubernetes cluster that pulls from the registry with an image pull secret. Deploy from CI to Kubernetes and Use a container registry with Kubernetes cover the cluster path.
Services involved#
| Service | Role in this architecture | Docs |
|---|---|---|
| Compute | Hosts the forge, the runner, the registry, and VM deploy targets | Compute |
| Network | Private networks, security groups, and floating IPs for each instance | Network |
| Kubernetes (Magnum) | Cluster deploy target that pulls images from the registry | Kubernetes |
| Object Storage | Optional store for build artifacts and remote state | Object Storage |
Get started#
Build the pipeline one stage at a time. Each template links its companion tutorial.
- Forgejo git and CI template and its deploy tutorial: a self-hosted forge with a bundled Actions runner. This is the source-and-build stage.
- Harbor registry template and its deploy tutorial: a self-hosted container registry. This is the registry stage.
- Deploy a CI runner: a standalone runner when you keep your repository on a hosted forge.
- Coolify host template: push-to-deploy onto a VM as the deploy stage.
- Next.js app template and its deploy tutorial: an application target to build and ship through the pipeline.
- Kubernetes cluster template: a Magnum cluster as the deploy stage.
- How-to pages that fill in individual steps: CI/CD integration patterns, Build and deploy an app from a CI VM, Run Ansible from CI, Deploy from CI to Kubernetes, and Use a container registry with Kubernetes.
Estimate the cost#
Monthly cost estimate
Pricing calculator ↗Sized as a custom package on shared vCPU.
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
Forgejo
s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Included in baseline
s1a.medium
4 shared vCPU, 4 GiB RAM, 0.5 Gbps
Compute + RAM rate basis
4 vCPU + 4 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.
Block storage (70 GiB)
70 GiB at $0.08/GiB/mo
Public IP (included)
1 included with the custom package
Package promotional discount
Flat −$5.00/mo on the custom package (same promotion as named plans).
Included at no charge
These line items are zero on Quake AI. Many other providers meter them separately.
Data transfer (inbound and outbound)
Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.
AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.
Learn morePrivate networking
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
Configure your estimate
Check the add-ons you plan to deploy to build a monthly total. Nothing is selected to start, so the total below begins at the baseline.
Starting template
The required baseline, always included.
Pricing data last validated: . For current rates, check quake.ai/pricing.
Considerations and limits#
- You operate every stage. Quake AI provides Compute, Network, and storage; the forge, the runner, the registry, and the deploy target are yours under the shared responsibility model. There is no platform-managed CI product.
- Single-node components. The Forgejo and Harbor templates each provision one VM with file-backed storage. For high availability, run the forge and registry against external Postgres and Object Storage and route requests through an edge reverse proxy.
- CPU-only compute. Runners are AMD EPYC with no GPU option (compute FAQ). Size the runner flavor to the build, and add runner instances or raise the runner capacity for more concurrent jobs.
- Authenticated registry over self-signed TLS. Harbor serves HTTPS only and generates a self-signed certificate on first boot; clients trust it before the first
docker login, or you install a CA-issued certificate on a domain. Use a robot account scoped to a project for pipeline and cluster credentials rather than the admin password. - Flat egress. Quake AI applies a no-egress-fee policy for outbound transfer, which suits image pulls from the registry on every deploy.
- Three US regions. All current regions are in the United States.
- When this pattern is not the right fit.
- Teams that want a managed CI product with no servers to operate.
- Teams that already run a hosted forge and registry and only need a runner, which the CI runner tutorial covers on its own.
- Teams whose primary need is IaC and state management rather than a build-and-deploy loop, covered by DevOps automation and CI/CD.