640 Free Linux VM on Google Cloud
0%

Free Always-On Linux VM on Google Cloud

The task: stand up an always-on e2-micro Linux server on Google Cloud that stays inside the permanent free tier, and serve a page from it.

about 30 minutes$0Gmail + credit cardproject jbj1 · VM g1 · us-central1-a
Steps
  1. •Before you start
  2. 11 — Account and gcloud
  3. 22 — Project and billing
  4. 33 — Enable the API
  5. 44 — Firewall and VM
  6. 55 — Connect
  7. 66 — Set up the server
  8. •Links
•

Before you start

Everything is done with gcloud. Run all commands from your own terminal, or from Cloud Shell — the >_ icon in the console, where gcloud is pre-installed and pre-authenticated.

Free tier rules — all must be true

SettingValue
Machine typee2-micro
Regionus-west1, us-central1, us-east1
Disk typepd-standard (not balanced)
Disk size≤ 30 GB
Running VMsOne, per billing account

Plus 1 GB/month egress. The limit is instance-hours per billing account across all projects — a second project does not give you a second free VM.

1

1 — Account and gcloud

Sign up at https://cloud.google.com → Get started for free → Individual → card details. You get $300 over 90 days plus the permanent free tier.

Install the CLI

Windows — or the installer at cloud.google.com/sdk/docs/install, keeping Bundled Python ticked:

powershell
winget install --id Google.CloudSDK

macOS

bash
brew install --cask google-cloud-sdk

Linux

bash
sudo snap install google-cloud-cli --classic

Open a new terminal, then:

bash
gcloud auth login
Do it in the console instead

Every step below can also be done at console.cloud.google.com. Each step here carries a matching console panel — pick either path, not both.

If you would rather not install anything, click the >_ (Activate Cloud Shell) icon in the top-right of the console: it opens a terminal with gcloud already installed and already logged in, so you can skip the install and gcloud auth login entirely.

2

2 — Project and billing

bash
gcloud projects create jbj1 --name="jbj1"
gcloud config set project jbj1
bash
gcloud billing accounts list
gcloud billing projects link jbj1 --billing-account=XXXXXX-XXXXXX-XXXXXX

Copy the ACCOUNT_ID from accounts list into the last command. If the project ID is taken, use jbj1-$RANDOM and substitute it everywhere below.

Do it in the console instead
  1. Open the project picker in the top bar → New project.
  2. Project name jbj1. Note the Project ID the form shows — if jbj1 was taken it appends digits, and that ID is what every later command needs. → Create.
  3. Make sure the project picker now shows jbj1.
  4. Billing in the left menu → Link a billing account → pick your account → Set account.
3

3 — Enable the API

bash
gcloud services enable compute.googleapis.com
Do it in the console instead
  1. APIs & Services → Library.
  2. Search Compute Engine API → open it → Enable.
  3. First enable takes a minute or two.
4

4 — Firewall and VM

Tags do nothing without matching rules:

bash
gcloud compute firewall-rules create allow-http \
  --allow=tcp:80 --target-tags=http-server --source-ranges=0.0.0.0/0

gcloud compute firewall-rules create allow-https \
  --allow=tcp:443 --target-tags=https-server --source-ranges=0.0.0.0/0
bash
gcloud compute instances create g1 \
  --zone=us-central1-a \
  --machine-type=e2-micro \
  --image-family=debian-13 \
  --image-project=debian-cloud \
  --boot-disk-type=pd-standard \
  --boot-disk-size=30GB \
  --network-tier=STANDARD \
  --tags=http-server,https-server \
  --metadata=enable-oslogin=FALSE,startup-script='#!/bin/bash
if [ ! -f /swapfile ]; then
  fallocate -l 2G /swapfile
  chmod 600 /swapfile
  mkswap /swapfile
  swapon /swapfile
  echo "/swapfile none swap sw 0 0" >> /etc/fstab
fi'
The startup script adds 2 GB swap — required, as 1 GB RAM will OOM without it. It runs as root on every boot, hence the if guard.

Get the IP

bash
gcloud compute instances describe g1 \
  --zone=us-central1-a \
  --format="get(networkInterfaces[0].accessConfigs[0].natIP)"
Do it in the console instead

The VM — Compute Engine → VM instances → Create instance:

  1. Name: g1.
  2. Region: us-central1, Zone: us-central1-a.
  3. Machine configuration: series E2 → machine type e2-micro. The form defaults to a bigger type; this one must be e2-micro or the VM is not free.
  4. OS and storage → Change: Debian → Debian GNU/Linux 13, boot disk type Standard persistent disk (the form defaults to Balanced, which is not free), size 30 GB → Select.
  5. Networking → Firewall: tick Allow HTTP traffic and Allow HTTPS traffic. This creates the two firewall rules and adds the http-server / https-server tags for you — which is why the console path needs no separate firewall step.
  6. Networking → Network interfaces → edit the interface → Network Service Tier: Standard.
  7. Advanced → Automation → Startup script: paste the same script as above (the #!/bin/bash block between the quotes).
  8. Create. The estimated cost panel on the right should read about $0.

The firewall rules — only needed if you missed the two tick boxes: VPC network → Firewall → Create firewall rule. Name allow-http, Targets Specified target tags → http-server, Source IPv4 ranges 0.0.0.0/0, Protocols and ports → TCP 80 → Create. Repeat with allow-https / https-server / TCP 443.

The IP — it is the External IP column on the VM instances list.

5

5 — Connect

bash
gcloud compute ssh g1 --zone=us-central1-a

There are no passwords on GCE VMs — keys only. gcloud generates and uploads one on first run.

Do it in the console instead
  1. Compute Engine → VM instances.
  2. On the g1 row click SSH → Open in browser window.
  3. A terminal opens in a new tab. No keys, no client to install — the console handles the key for you. Continue with step 6 in that window.
6

6 — Set up the server

bash
free -h                      # Swap row shows 2.0Gi
sudo apt update && sudo apt upgrade -y
sudo apt install -y nginx
echo "<h1>Hello from g1</h1>" | sudo tee /var/www/html/index.html

Open http://YOUR_EXTERNAL_IP in a browser. Use http://, not https://.

⚠ 1 GB egress per month. Fine for text, exhausted quickly by images or large scp transfers, then about $0.12/GB.