Before you start
gcloud. Run all commands from your own terminal, or from Cloud Shell — the >_ icon in the console, where gcloud is pre-installed and pre-authenticated.Free tier rules — all must be true
| Setting | Value |
|---|---|
| Machine type | e2-micro |
| Region | us-west1, us-central1, us-east1 |
| Disk type | pd-standard (not balanced) |
| Disk size | ≤ 30 GB |
| Running VMs | One, per billing account |
Plus 1 GB/month egress. The limit is instance-hours per billing account across all projects — a second project does not give you a second free VM.
1 — Account and gcloud
Sign up at https://cloud.google.com → Get started for free → Individual → card details. You get $300 over 90 days plus the permanent free tier.
Install the CLI
Windows — or the installer at cloud.google.com/sdk/docs/install, keeping Bundled Python ticked:
winget install --id Google.CloudSDKmacOS
brew install --cask google-cloud-sdkLinux
sudo snap install google-cloud-cli --classicOpen a new terminal, then:
gcloud auth loginDo it in the console instead
Every step below can also be done at console.cloud.google.com. Each step here carries a matching console panel — pick either path, not both.
If you would rather not install anything, click the >_ (Activate Cloud Shell) icon in the top-right of the console: it opens a terminal with gcloud already installed and already logged in, so you can skip the install and gcloud auth login entirely.
2 — Project and billing
gcloud projects create jbj1 --name="jbj1"
gcloud config set project jbj1gcloud billing accounts list
gcloud billing projects link jbj1 --billing-account=XXXXXX-XXXXXX-XXXXXXCopy the ACCOUNT_ID from accounts list into the last command. If the project ID is taken, use jbj1-$RANDOM and substitute it everywhere below.
Do it in the console instead
- Open the project picker in the top bar → New project.
- Project name
jbj1. Note the Project ID the form shows — ifjbj1was taken it appends digits, and that ID is what every later command needs. → Create. - Make sure the project picker now shows
jbj1. - Billing in the left menu → Link a billing account → pick your account → Set account.
3 — Enable the API
gcloud services enable compute.googleapis.comDo it in the console instead
- APIs & Services → Library.
- Search Compute Engine API → open it → Enable.
- First enable takes a minute or two.
4 — Firewall and VM
Tags do nothing without matching rules:
gcloud compute firewall-rules create allow-http \
--allow=tcp:80 --target-tags=http-server --source-ranges=0.0.0.0/0
gcloud compute firewall-rules create allow-https \
--allow=tcp:443 --target-tags=https-server --source-ranges=0.0.0.0/0gcloud compute instances create g1 \
--zone=us-central1-a \
--machine-type=e2-micro \
--image-family=debian-13 \
--image-project=debian-cloud \
--boot-disk-type=pd-standard \
--boot-disk-size=30GB \
--network-tier=STANDARD \
--tags=http-server,https-server \
--metadata=enable-oslogin=FALSE,startup-script='#!/bin/bash
if [ ! -f /swapfile ]; then
fallocate -l 2G /swapfile
chmod 600 /swapfile
mkswap /swapfile
swapon /swapfile
echo "/swapfile none swap sw 0 0" >> /etc/fstab
fi'if guard.Get the IP
gcloud compute instances describe g1 \
--zone=us-central1-a \
--format="get(networkInterfaces[0].accessConfigs[0].natIP)"Do it in the console instead
The VM — Compute Engine → VM instances → Create instance:
- Name:
g1. - Region:
us-central1, Zone:us-central1-a. - Machine configuration: series E2 → machine type e2-micro. The form defaults to a bigger type; this one must be
e2-microor the VM is not free. - OS and storage → Change: Debian → Debian GNU/Linux 13, boot disk type Standard persistent disk (the form defaults to Balanced, which is not free), size 30 GB → Select.
- Networking → Firewall: tick Allow HTTP traffic and Allow HTTPS traffic. This creates the two firewall rules and adds the
http-server/https-servertags for you — which is why the console path needs no separate firewall step. - Networking → Network interfaces → edit the interface → Network Service Tier: Standard.
- Advanced → Automation → Startup script: paste the same script as above (the
#!/bin/bashblock between the quotes). - Create. The estimated cost panel on the right should read about $0.
The firewall rules — only needed if you missed the two tick boxes: VPC network → Firewall → Create firewall rule. Name allow-http, Targets Specified target tags → http-server, Source IPv4 ranges 0.0.0.0/0, Protocols and ports → TCP 80 → Create. Repeat with allow-https / https-server / TCP 443.
The IP — it is the External IP column on the VM instances list.
5 — Connect
gcloud compute ssh g1 --zone=us-central1-aThere are no passwords on GCE VMs — keys only. gcloud generates and uploads one on first run.
Do it in the console instead
- Compute Engine → VM instances.
- On the
g1row click SSH → Open in browser window. - A terminal opens in a new tab. No keys, no client to install — the console handles the key for you. Continue with step 6 in that window.
6 — Set up the server
free -h # Swap row shows 2.0Gi
sudo apt update && sudo apt upgrade -y
sudo apt install -y nginx
echo "<h1>Hello from g1</h1>" | sudo tee /var/www/html/index.htmlOpen http://YOUR_EXTERNAL_IP in a browser. Use http://, not https://.
scp transfers, then about $0.12/GB.