COMP141 - Lab 3 - GCP Setup
Guide 3: Launching & Connecting to Your Free-Tier Linux Instance
This guide walks you through creating a free, cloud-hosted Linux virtual machine (VM) on Google Cloud Platform and connecting to it via SSH (Secure Shell).
GCP Free Tier VM Rules
Google Cloud provides one free VM instance per account under the Always Free program, provided you match these exact settings:
| Setting | Free Tier Value | Notes |
|---|---|---|
| Machine Type | e2-micro (2 vCPU, 1 GB RAM) |
Do NOT select e2-small or e2-medium. |
| Region | us-central1 (Iowa)us-east1 (S. Carolina)us-west1 (Oregon) |
Must pick one of these 3 US regions. |
| Boot Disk Type | Standard Persistent Disk (pd-standard) |
Crucial: Change default “Balanced” or “SSD” to Standard. |
| Boot Disk Size | 30 GB or less | Up to 30 GB total disk per month is free. |
| Network Egress | 1 GB per month (excluding China & Australia) | Sufficient for all course exercises. |
Part 1: Enabling Compute Engine & Creating the VM
Step 1: Navigate to Compute Engine
- Open Google Cloud Console.
- Open the Navigation Menu (the ☰ hamburger menu).
- Hover over Compute Engine and click VM instances.
- If prompted to enable the Compute Engine API, click Enable and wait a moment for initialization.
Step 2: Configure VM Instance Details
Click the Create Instance button at the top of the VM instances page. Configure the following fields carefully:
1. Name & Region
- Name: Enter
comp141-linux-vm(use lower-case letters, numbers, and hyphens only). - Region: Choose one of the approved free regions:
us-central1 (Iowa)(recommended)us-east1 (South Carolina)us-west1 (Oregon)
- Zone: Any zone (e.g.,
us-central1-a).
2. Machine Configuration
- Preset: Select General-purpose.
- Series: Select E2.
- Machine type: Select e2-micro (2 vCPU, 1 GB memory).
You will see an estimated monthly cost on the right side of the screen. As long as you follow the free-tier parameters, your free credits/free tier allowance will cover this cost ($0 out-of-pocket).
3. Boot Disk (CRITICAL STEP)
By default, GCP selects a Balanced Persistent Disk. You must change this to stay in the Free Tier!
- Under the Boot disk section, click Change.
- Operating System: Select Debian or Ubuntu.
- Recommended: Debian GNU/Linux 12 (bookworm) or Ubuntu 24.04 LTS.
- Boot disk type: Change from “Balanced Persistent Disk” to Standard Persistent Disk.
- Size (GB): Enter
30. - Click Select at the bottom of the pop-up.
4. Firewall & Networking
- Ensure SSH access is allowed (enabled by default on GCP VMs).
5. Create the Instance
Double-check all settings against the table above, then click Create at the bottom of the page. Wait 30–60 seconds for the VM to start (a green checkmark will appear next to comp141-linux-vm).
6. Identify Your VM’s External IP Address
Once the VM finishes launching:
- You will be on the VM instances page (
Compute Engine > VM instances). - Look at the table of virtual machines and locate the row for
comp141-linux-vm. - Find the column labeled External IP (located between Internal IP and Connect).
- You will see a public IPv4 address (e.g.,
34.123.45.67):- Hover over the address and click the Copy IP address icon (📋) next to it to copy it to your clipboard.
- Do not confuse this with the Internal IP (which usually starts with
10.x.x.xand is only accessible within Google Cloud’s private network). - Reminder: This address is ephemeral. If you stop and restart your instance, Google will assign a new External IP. Always check this column after starting the VM.
Step 3: Enable Incoming UDP Traceroute in GCP Firewall
By default, Google Cloud’s firewall allows ping (ICMP) and SSH (TCP port 22), but blocks unsolicited incoming UDP traffic. Because standard Unix and macOS traceroute commands probe destinations using UDP ports 33434–33534, traceroute packets sent to your VM’s external IP will time out (* * *) at the final hop unless we open this port range.
To configure your firewall so the VM responds to incoming UDP traceroute requests:
- In the Google Cloud Console, open the Navigation Menu (☰) in the top-left corner.
- Navigate to VPC network > Firewall.
- Click + Create Firewall Rule at the top of the page.
- Fill in the following details:
- Name:
allow-udp-traceroute - Network:
default - Priority:
1000(default) - Direction of traffic:
Ingress - Action on match:
Allow - Targets: Select All instances in the network.
- Source IPv4 ranges: Enter
0.0.0.0/0. - Protocols and ports:
- Check Specified protocols and ports.
- Check UDP.
- Enter port range:
33434-33534.
- Name:
- Click Create at the bottom.
[!NOTE] Creating firewall rules in Google Cloud is completely free of charge. Because this rule targets All instances in the network, your
comp141-linux-vmwill immediately respond to incoming traceroute probes without any additional setup.
Part 2: Connecting to Your VM via In-Browser SSH
For most class exercises, connecting directly through your web browser is the quickest and easiest method—no extra software installation or SSH key configuration is required.
(If you would like to connect from your local terminal or manage instances from the command line using gcloud, see Guide 4: Your VM from the CLI).
Connecting with GCP In-Browser SSH
- Return to Compute Engine > VM instances in the Google Cloud Console.
- Find
comp141-linux-vmin your list of instances. - In the Connect column, click the SSH button.
- A new browser window will open, automatically establishing an encrypted SSH connection to your Linux terminal.
- Once loaded, you will see a Linux command prompt similar to:
username@comp141-linux-vm:~$
Part 3: Essential First Linux Commands
Once connected to your shell, verify your system configuration by executing these introductory commands:
- Check OS Details:
cat /etc/os-release - Check System Architecture & Kernel:
uname -a - Check Available Disk Space:
df -h - Update Package Manager:
sudo apt update && sudo apt upgrade -y - Install Essential Tools (e.g.,
git,curl,nano,tmux,build-essential):sudo apt install -y git curl nano tmux build-essential
Part 4: Testing Network Connectivity (Ping & Traceroute)
You can verify that your VM and firewall rules are working properly by testing network connectivity from your personal computer’s terminal:
- Look at your VM on the VM instances page and copy its External IP address.
- Open a terminal or PowerShell prompt on your personal computer:
- Test Ping:
ping <EXTERNAL_IP>(Press
Ctrl+Cto stop). The VM should immediately return ICMP replies. - Test Traceroute:
- On macOS or Linux (uses UDP ports 33434–33534):
traceroute <EXTERNAL_IP> - On Windows (uses ICMP):
tracert <EXTERNAL_IP>
- On macOS or Linux (uses UDP ports 33434–33534):
- Test Ping:
- Because we added the
allow-udp-traceroutefirewall rule, the traceroute will show every network hop all the way to your VM’s external IP at the final hop!
Managing Your VM (Stopping & Starting)
- Stopping your VM: When not working on assignments for extended periods, you can stop the VM to conserve compute resources.
- In GCP Console, check the box next to
comp141-linux-vmand click Stop ⏹ at the top. - Alternatively, run
sudo shutdown -h nowinside the SSH terminal.
- In GCP Console, check the box next to
- Restarting your VM: Select
comp141-linux-vmin GCP Console and click Start / Resume ▶.Note on IP Addresses: When you stop and restart a VM, its External IP address may change (ephemeral IP). Use the new External IP or the GCP Browser SSH button to reconnect.
Troubleshooting Checklist
| Problem | Cause | Solution |
|---|---|---|
| SSH connection times out | Firewall blocking port 22 or VM starting up | Wait 1 minute and retry. Ensure default network firewall rules allow SSH. |
Traceroute times out (* * *) |
Ingress firewall blocking UDP ports 33434–33534 | Ensure the allow-udp-traceroute rule is created under VPC network > Firewall with target All instances in the network. |
| Billed unexpectedly | Selected SSD or non-free region/machine type | Go to VM details, check disk type (must be Standard Persistent Disk) and machine type (e2-micro). |
| Browser pop-up blocked | Browser blocked the new SSH window | Allow pop-ups from console.cloud.google.com in your browser address bar. |