What you need
- A GCP project with billing enabled
- The
gcloudCLI or the Cloud Console - SSH access from your laptop
- Model and optional channel credentials
- About 20 minutes
Provision the VM
1
Initialize gcloud
Install the CLI from
cloud.google.com/sdk/docs/install,
then authenticate:You can perform the same steps in the Cloud Console.
2
Create the project
3
Choose a machine
Create a Debian 12 VM:
4
Review firewall access
Keep TCP 18789 closed to the public Internet. The SSH tunnel below needs
only SSH access to the VM:Restrict SSH source ranges to your administrative network when possible.
If you intentionally expose the Gateway through a reverse proxy or tailnet,
follow Gateway security rather than adding a broad
0.0.0.0/0 rule for port 18789.5
Connect over SSH
6
Install Docker
On the VM:Reconnect so the group change takes effect, then verify the installation:
Configure the Docker runtime
On the VM, follow Docker VM runtime from Before you begin through Verify and administer the Gateway. The maintained setup script uses these GCP host paths by default:Killed, ResourceExhausted, or exit code 137,
resize the VM before retrying.
Access the Control UI
From your laptop, open an SSH tunnel and leave it running:http://127.0.0.1:18789/. Paste the Gateway token from the VM’s .env
when prompted. To reprint the dashboard URL or approve a browser device, run on
the VM: