Self-hosted secrets management
Self-hosted secrets management
Centralize API keys, database credentials, and other secrets on a self-hosted Infisical instance. You operate projects, environments, and access policies; Quake AI provides the Compute instance, network, and block storage the platform runs on.
What this is for#
Teams that store credentials in .env files, chat messages, or a spreadsheet need a single place to version secrets per environment and control who can read them. Infisical (a self-hosted alternative to Doppler or 1Password Secrets) gives a team that place: projects, environments, versioned secret history, and role-based access, running on infrastructure you own instead of a third-party SaaS. The outcome is a secrets store your CI jobs, quake.yaml launch manifests, and local development environments read from, deployable from a validated OpenTofu template and its companion tutorial.
Reference architecture#
Download diagram: SVG, PNG, and PDF.
The base is a single validated template: Infisical secrets management provisions the instance, network, and volume Infisical runs on.
-
Team members and CI jobs. Developers manage secrets through Infisical's web UI; CI pipelines and running services read secrets through Infisical's CLI or SDKs.
-
Reverse proxy. The edge reverse proxy template terminates HTTPS on a floating IP and forwards to Infisical on the private subnet, since Infisical needs a public URL for auth callbacks and CLI/SDK logins.
-
Infisical app. The Infisical secrets management template runs Infisical in Docker on a Compute instance, alongside a bundled PostgreSQL and Redis.
-
Bundled datastore. PostgreSQL stores secrets, projects, and access policies; Redis handles caching and background jobs. Both run as containers on the same instance, backed by a Block Storage volume.
Services involved#
| Service | Role in this architecture | Docs |
|---|---|---|
| Compute | Hosts Infisical, PostgreSQL, and Redis | Compute |
| Network | Private network, security group, and floating IP for public access | Network |
| Block Storage | Volume backing the database and Redis data | Block Storage |
Get started#
- Infisical secrets management template: OpenTofu pattern that provisions the instance, network, and volume, and generates
ENCRYPTION_KEY,AUTH_SECRET, and the database password on first boot. - OpenTofu template library: browse validated IaC starting points for other self-hosted team tools.
Estimate the cost#
Monthly cost estimate
Pricing calculator ↗Sized as a custom package on shared vCPU.
Monthly total for the required template above. Use the configurator below to add optional pieces and see the total update.
What each resource is for
Infisical secrets-management host
s1a.medium · 4 shared vCPU, 4 GiB RAM, 0.5 Gbps
Runs Infisical in Docker (the secrets-management app) alongside its bundled PostgreSQL and Redis, with the database and Redis data on an attached volume.
Infisical plus its bundled PostgreSQL and Redis runs on 4 vCPU and 4 GiB RAM. Size up for large teams or heavy secret-access volume.
Compute shown per role at custom-package rates ($29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM). The headline above is the billed total: the cheaper of a named plan and the custom package, plus add-ons.
Included in baseline
s1a.medium
4 shared vCPU, 4 GiB RAM, 0.5 Gbps
Compute + RAM rate basis
4 vCPU + 4 GiB RAM at $29/dedicated vCPU, $7.25/shared vCPU, $1/GiB RAM (regular). Totals apply the flat −$5/mo package promotion.
Block storage (50 GiB)
50 GiB at $0.08/GiB/mo
Public IP (included)
1 included with the custom package
Package promotional discount
Flat −$5.00/mo on the custom package (same promotion as named plans).
Included at no charge
These line items are zero on Quake AI. Many other providers meter them separately.
Data transfer (inbound and outbound)
Unlimited data transfer on every plan; Quake AI does not meter per-GB egress.
AWS, GCP, and Azure meter outbound transfer per GB. DigitalOcean and Hetzner include an allowance on compute plans, then charge overage.
Learn morePrivate networking
Private networks, subnets, Neutron routers, and security groups are included with the plan.
VPC objects are usually free to create elsewhere, but NAT gateways bill hourly plus per-GB processed. Quake AI uses router SNAT with no separate NAT line item.
Control-plane API requests
OpenStack API calls for provisioning and management are included.
Some managed services on other clouds meter API calls or charge for premium control-plane features.
Configure your estimate
Check the add-ons you plan to deploy to build a monthly total. Nothing is selected to start, so the total below begins at the baseline.
Starting template
The required baseline, always included.
Pricing data last validated: . For current rates, check quake.ai/pricing.
Considerations and limits#
- You operate the credential lifecycle. Quake AI provisions the instance; project structure, environment policies, key rotation, and access reviews are yours under the shared responsibility model.
- Back up
ENCRYPTION_KEYimmediately.ENCRYPTION_KEYencrypts every stored secret. Losing it makes every stored secret permanently unrecoverable, with no recovery path. Copy/opt/infisical/.envto a secure location outside the instance before you store any real secrets. - Single-instance bundled datastore. The bundled PostgreSQL and Redis suit a single-team deployment. To scale the database independently, point Infisical at a self-managed PostgreSQL instance instead.
- Flat egress. Quake AI applies a no-egress-fee policy for outbound transfer, which keeps CI jobs reading secrets at scale predictable.
- Three US regions. All current regions are in the United States.
- Compliance posture. Quake AI holds SOC 2 Type I and Type II attestations and SOC 3. See Compliance and certifications for the platform scope.