Skip to content
Solutions

Self-hosted secrets management

Self-hosted secrets management

Centralize API keys, database credentials, and other secrets on a self-hosted Infisical instance. You operate projects, environments, and access policies; Quake AI provides the Compute instance, network, and block storage the platform runs on.

What this is for#

Teams that store credentials in .env files, chat messages, or a spreadsheet need a single place to version secrets per environment and control who can read them. Infisical (a self-hosted alternative to Doppler or 1Password Secrets) gives a team that place: projects, environments, versioned secret history, and role-based access, running on infrastructure you own instead of a third-party SaaS. The outcome is a secrets store your CI jobs, quake.yaml launch manifests, and local development environments read from, deployable from a validated OpenTofu template and its companion tutorial.

Reference architecture#

Team members and CI jobsReverse proxy (HTTPS)Quake AIinfisical-secrets templateInfisical appBundled PostgreSQL + Redis read and write secretsHTTPS:8080
Click to zoom
Secrets management on Quake AI: team members and CI reach Infisical over HTTPS through a reverse proxy; Infisical stores secrets in a bundled PostgreSQL and uses Redis for caching, both on the infisical-secrets template's instance

Download diagram: SVG, PNG, and PDF.

The base is a single validated template: Infisical secrets management provisions the instance, network, and volume Infisical runs on.

  1. Team members and CI jobs. Developers manage secrets through Infisical's web UI; CI pipelines and running services read secrets through Infisical's CLI or SDKs.

  2. Reverse proxy. The edge reverse proxy template terminates HTTPS on a floating IP and forwards to Infisical on the private subnet, since Infisical needs a public URL for auth callbacks and CLI/SDK logins.

  3. Infisical app. The Infisical secrets management template runs Infisical in Docker on a Compute instance, alongside a bundled PostgreSQL and Redis.

  4. Bundled datastore. PostgreSQL stores secrets, projects, and access policies; Redis handles caching and background jobs. Both run as containers on the same instance, backed by a Block Storage volume.

Services involved#

ServiceRole in this architectureDocs
ComputeHosts Infisical, PostgreSQL, and RedisCompute
NetworkPrivate network, security group, and floating IP for public accessNetwork
Block StorageVolume backing the database and Redis dataBlock Storage

Get started#

Estimate the cost#

Monthly cost estimate

Pricing calculator ↗

Sized as a custom package on shared vCPU.

Starting template$32.00/mo

Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.

What each resource is for

Infisical secrets-management host

s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps

Runs Infisical in Docker (the secrets-management app) alongside its bundled PostgreSQL and Redis, with the database and Redis data on an attached volume.

Infisical plus its bundled PostgreSQL and Redis runs on 4 vCPU and 4 GiB RAM. Size up for large teams or heavy secret-access volume.

$33.00/mo

Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.

Included in baseline

s1a.medium

4 shared vCPU, 4 GiB RAM, 0.5 Gbps

$33.00

Compute + RAM rate basis

4 vCPU + 4 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.

—

Block storage (50 GiB)

50 GiB at $0.08/GiB/mo

$4.00

Public IP (included)

1 included with the custom package

$0.00

Package promotional discount

Flat −$5.00/mo on the custom package (same promotion as named plans).

$-5.00

Included at no charge

These line items are zero on Quake AI. Many other providers meter them separately.

Data transfer (inbound and outbound)

Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.

AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.

Learn more
$0.00

Private networking

Private networks, subnets, Neutron routers, and security groups are included with the plan.

VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.

$0.00

Control-plane API requests

OpenStack API calls for provisioning and management are included.

Some managed services on other clouds meter API calls or charge for premium control-plane features.

$0.00

Configure your estimate

Check the add-ons you plan to deploy to build a monthly total. Nothing is selected to start, so the total below begins at the baseline.

Starting template

The required baseline, always included.

$32.00/mo
Your configured estimate$32.00/mo

Pricing data last validated: . For current rates, check quake.ai/pricing.

Considerations and limits#

  • You operate the credential lifecycle. Quake AI provisions the instance; project structure, environment policies, key rotation, and access reviews are yours under the shared responsibility model.
  • Back up ENCRYPTION_KEY immediately. ENCRYPTION_KEY encrypts every stored secret. Losing it makes every stored secret permanently unrecoverable, with no recovery path. Copy /opt/infisical/.env to a secure location outside the instance before you store any real secrets.
  • Single-instance bundled datastore. The bundled PostgreSQL and Redis suit a single-team deployment. To scale the database independently, point Infisical at a self-managed PostgreSQL instance instead.
  • Flat egress. Quake AI applies a no-egress-fee policy for outbound transfer, which keeps CI jobs reading secrets at scale predictable.
  • Three US regions. All current regions are in the United States.
  • Compliance posture. Quake AI holds SOC 2 Type I and Type II attestations and SOC 3. See Compliance and certifications for the platform scope.
Was this page helpful?