Single-VM server
The server profile runs Abada on one public host: PostgreSQL, Engine,
Studio, the docs, the Agent Worker and a bundled Keycloak in production mode,
behind Traefik with Let’s Encrypt certificates. Use it for evaluations and
public demos on a cloud VM when you do not run your own identity provider.
Every hostname comes from one ABADA_DOMAIN:
| URL | Service |
|---|---|
https://$ABADA_DOMAIN |
Studio; /api on the same origin goes to the engine |
https://api.$ABADA_DOMAIN |
Engine API for external workers and SDK clients |
https://auth.$ABADA_DOMAIN |
Keycloak, realm abada |
https://docs.$ABADA_DOMAIN |
Documentation |
Prerequisites
Section titled “Prerequisites”- A Linux VM with Docker Engine and Compose v2. About 8 GB of memory
(
e2-standard-2on Google Cloud); add more for bundled telemetry. - Ports 80 and 443 open to the internet. Port 80 serves the ACME challenge and the HTTPS redirect.
- Two DNS
Arecords pointing at the VM: the domain and its wildcard, for exampledemo.example.organd*.demo.example.org. On Cloudflare, set them to DNS only so certificate validation reaches the VM.
Without a domain, use <ip-with-dashes>.sslip.io (for example
34-56-78-90.sslip.io); every subdomain resolves to that address and Let’s
Encrypt issues certificates for it.
-
Install the release bundle and prepare
.env.serverwithout starting anything:Terminal window curl -fsSL https://raw.githubusercontent.com/bashizip/abada-platform/main/release/quickstart.sh -o quickstart.shABADA_PROFILE=server ABADA_VERSION=1.0.0-rc.7 bash quickstart.shThe script verifies the archive checksum, extracts it and creates
.env.server. From an already extracted archive, running the start command in step 3 once creates the file instead. -
Set the two required values in
.env.server:Terminal window ABADA_DOMAIN=demo.example.orgABADA_ACME_EMAIL=ops@example.orgLeave the secrets empty.
-
Start the platform:
Terminal window ./release/abada-platform up server
On first start the launcher generates every secret into .env.server (mode
600): database passwords, the Keycloak admin password, client secrets and
the Studio passwords. On every start it validates the domain, email, secrets
and pinned image versions, then:
- sets the Studio client’s redirect URI and web origin to your domain;
- creates or updates
alice, the operator with every Abada role, andbob, a reviewer who can run processes and complete tasks but cannot deploy or administer; - provisions and starts the Agent Worker.
Each step is idempotent, so rerunning up server applies a changed
.env.server. Read the passwords from the file:
grep -E '^(ABADA_OPERATOR_PASSWORD|ABADA_REVIEWER_PASSWORD|KEYCLOAK_ADMIN_PASSWORD)=' .env.serverCertificates are requested on the first HTTPS request to each hostname; allow up to a minute on the first page load.
First run
Section titled “First run”- Open
https://$ABADA_DOMAINand sign in asalice. The first sign-in creates and deploys the AI Lead Triage starter and addsbobas its reviewer. - Add your model provider key in Studio → Settings, or set
ABADA_AGENT_LLM_API_KEYin.env.serverand rerunup server. - Follow your first agentic workflow.
Google Cloud
Section titled “Google Cloud”The release bundle includes deployment/gcp/startup.sh, a Compute Engine
startup script for Debian 12 and Ubuntu. On every boot it installs Docker,
downloads and verifies the release bundle into /opt/abada and writes the
domain and email from instance metadata into .env.server. It starts the
platform only when the metadata attribute abada-autostart is true.
gcloud compute instances create abada-demo --machine-type e2-standard-2 --image-family debian-12 --image-project debian-cloud --boot-disk-size 30GB --address abada-demo-ip --tags abada-web --metadata-from-file startup-script=deployment/gcp/startup.sh --metadata abada-domain=demo.example.org,abada-acme-email=ops@example.org,abada-version=1.0.0-rc.7Then connect to the VM and run sudo /opt/abada/release/abada-platform up server.
The full procedure, including the static address, firewall rule, DNS, backups
and upgrades, is in the
GCP operations guide.
Running a public demo
Section titled “Running a public demo”- Model spend. Every started instance calls the model. Use a provider key
with a spending cap;
ABADA_AGENT_MAX_TASKS=2limits concurrency. - Shared accounts. Anyone with bob’s password can start and complete work.
Change
ABADA_REVIEWER_PASSWORDand rerunup serverto rotate it, or setABADA_REVIEWER_ENABLED=falseto disable the account. - Rehearsals. Set
ABADA_ACME_CA_SERVERtohttps://acme-staging-v02.api.letsencrypt.org/directoryto avoid Let’s Encrypt rate limits. Browsers do not trust staging certificates.
Stop without deleting data:
./release/abada-platform down server