Skip to content
Solutions

Internal tools and admin panels

Internal tools and admin panels

Build internal tools, admin panels, and database-backed UIs on a self-hosted Appsmith Community Edition instance. You operate apps, datasources, and access; Quake AI provides the Compute instance, network, and block storage the platform runs on.

What this is for#

Teams that need an admin panel, an internal dashboard, or a database-backed UI without writing a frontend from scratch use a low-code builder. Appsmith Community Edition (a self-hosted alternative to Retool) gives a team that builder, running on infrastructure you own instead of a per-seat SaaS. The outcome is a low-code platform for internal tools, deployable from a validated OpenTofu template and its companion tutorial.

Reference architecture#

Team membersReverse proxy (HTTPS, optional)Quake AIappsmith-internal-tools templateDatasources you connect (Postgres, REST APIs)Appsmith app (embedded MongoDB + Redis) queriesHTTPS:8080
Click to zoom
Internal tools on Quake AI: team members reach Appsmith over HTTPS through an optional reverse proxy; Appsmith's single container (with embedded MongoDB and Redis) queries datasources you connect, such as Postgres or REST APIs

Download diagram: SVG, PNG, and PDF.

The base is a single validated template: Appsmith internal tools provisions the instance, network, and volume Appsmith runs on.

  1. Team members. Developers build apps in Appsmith's UI; end users interact with the published internal tools and admin panels.

  2. Reverse proxy (optional). For production use, the edge reverse proxy template terminates HTTPS on a floating IP in front of Appsmith. Appsmith is reachable immediately after boot without one.

  3. Appsmith app. The Appsmith internal tools template runs Appsmith Community Edition's single container, bundling the app server, an embedded MongoDB, and an embedded Redis, on a Compute instance.

  4. Datasources you connect. Appsmith queries the databases and APIs you configure as datasources (Postgres, MySQL, REST APIs, and others) from inside your apps; those datasources are not provisioned by this template.

Services involved#

ServiceRole in this architectureDocs
ComputeHosts Appsmith's app server and its embedded MongoDB and RedisCompute
NetworkPrivate network, security group, and floating IP for public accessNetwork
Block StorageVolume backing the /appsmith-stacks persistent stateBlock Storage

Get started#

  • Appsmith internal tools template: OpenTofu pattern that provisions the instance, network, and volume, and generates APPSMITH_ENCRYPTION_PASSWORD and APPSMITH_ENCRYPTION_SALT on first boot.
  • OpenTofu template library: browse validated IaC starting points for other self-hosted team tools.

Estimate the cost#

Monthly cost estimate

Pricing calculator ↗

Sized as a custom package on shared vCPU.

Starting template$32.00/mo

Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.

What each resource is for

Appsmith internal-tools host

s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps

Runs Appsmith Community Edition's single fat container (app server, embedded MongoDB, and embedded Redis in one image), with all persistent state under the /appsmith-stacks bind mount on an attached volume.

Appsmith's fat container runs on 4 vCPU and 4 GiB RAM. Size up for many concurrent users or large datasource query volume.

$33.00/mo

Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.

Included in baseline

s1a.medium

4 shared vCPU, 4 GiB RAM, 0.5 Gbps

$33.00

Compute + RAM rate basis

4 vCPU + 4 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.

—

Block storage (50 GiB)

50 GiB at $0.08/GiB/mo

$4.00

Public IP (included)

1 included with the custom package

$0.00

Package promotional discount

Flat −$5.00/mo on the custom package (same promotion as named plans).

$-5.00

Included at no charge

These line items are zero on Quake AI. Many other providers meter them separately.

Data transfer (inbound and outbound)

Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.

AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.

Learn more
$0.00

Private networking

Private networks, subnets, Neutron routers, and security groups are included with the plan.

VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.

$0.00

Control-plane API requests

OpenStack API calls for provisioning and management are included.

Some managed services on other clouds meter API calls or charge for premium control-plane features.

$0.00

Pricing data last validated: . For current rates, check quake.ai/pricing.

Considerations and limits#

  • You operate app and datasource access. Quake AI provisions the instance; app permissions, datasource credentials, and audit review are yours under the shared responsibility model.
  • Back up the encryption password and salt. APPSMITH_ENCRYPTION_PASSWORD and APPSMITH_ENCRYPTION_SALT encrypt stored datasource credentials at rest. Losing them makes stored datasource credentials unrecoverable. Copy /opt/appsmith/.env to a secure location before you connect any real datasource.
  • All persistent state lives on one volume. There is no separate datastore to point elsewhere: everything, including the embedded database, lives under /appsmith-stacks on the attached volume.
  • Flat egress. Quake AI applies a no-egress-fee policy for outbound transfer.
  • Three US regions. All current regions are in the United States.
  • Compliance posture. Quake AI holds SOC 2 Type I and Type II attestations and SOC 3. See Compliance and certifications for the platform scope.
Was this page helpful?