Skip to content

Single-VM server

The server profile runs Abada on one public host: PostgreSQL, Engine, Studio, the docs, the Agent Worker and a bundled Keycloak in production mode, behind Traefik with Let’s Encrypt certificates. Use it for evaluations and public demos on a cloud VM when you do not run your own identity provider.

Every hostname comes from one ABADA_DOMAIN:

URL Service
https://$ABADA_DOMAIN Studio; /api on the same origin goes to the engine
https://api.$ABADA_DOMAIN Engine API for external workers and SDK clients
https://auth.$ABADA_DOMAIN Keycloak, realm abada
https://docs.$ABADA_DOMAIN Documentation
  • A Linux VM with Docker Engine and Compose v2. About 8 GB of memory (e2-standard-2 on Google Cloud); add more for bundled telemetry.
  • Ports 80 and 443 open to the internet. Port 80 serves the ACME challenge and the HTTPS redirect.
  • Two DNS A records pointing at the VM: the domain and its wildcard, for example demo.example.org and *.demo.example.org. On Cloudflare, set them to DNS only so certificate validation reaches the VM.

Without a domain, use <ip-with-dashes>.sslip.io (for example 34-56-78-90.sslip.io); every subdomain resolves to that address and Let’s Encrypt issues certificates for it.

  1. Install the release bundle and prepare .env.server without starting anything:

    Terminal window
    curl -fsSL https://raw.githubusercontent.com/bashizip/abada-platform/main/release/quickstart.sh -o quickstart.sh
    ABADA_PROFILE=server ABADA_VERSION=1.0.0-rc.7 bash quickstart.sh

    The script verifies the archive checksum, extracts it and creates .env.server. From an already extracted archive, running the start command in step 3 once creates the file instead.

  2. Set the two required values in .env.server:

    Terminal window
    ABADA_DOMAIN=demo.example.org
    ABADA_ACME_EMAIL=ops@example.org

    Leave the secrets empty.

  3. Start the platform:

    Terminal window
    ./release/abada-platform up server

On first start the launcher generates every secret into .env.server (mode 600): database passwords, the Keycloak admin password, client secrets and the Studio passwords. On every start it validates the domain, email, secrets and pinned image versions, then:

  • sets the Studio client’s redirect URI and web origin to your domain;
  • creates or updates alice, the operator with every Abada role, and bob, a reviewer who can run processes and complete tasks but cannot deploy or administer;
  • provisions and starts the Agent Worker.

Each step is idempotent, so rerunning up server applies a changed .env.server. Read the passwords from the file:

Terminal window
grep -E '^(ABADA_OPERATOR_PASSWORD|ABADA_REVIEWER_PASSWORD|KEYCLOAK_ADMIN_PASSWORD)=' .env.server

Certificates are requested on the first HTTPS request to each hostname; allow up to a minute on the first page load.

  1. Open https://$ABADA_DOMAIN and sign in as alice. The first sign-in creates and deploys the AI Lead Triage starter and adds bob as its reviewer.
  2. Add your model provider key in Studio → Settings, or set ABADA_AGENT_LLM_API_KEY in .env.server and rerun up server.
  3. Follow your first agentic workflow.

The release bundle includes deployment/gcp/startup.sh, a Compute Engine startup script for Debian 12 and Ubuntu. On every boot it installs Docker, downloads and verifies the release bundle into /opt/abada and writes the domain and email from instance metadata into .env.server. It starts the platform only when the metadata attribute abada-autostart is true.

Terminal window
gcloud compute instances create abada-demo --machine-type e2-standard-2 --image-family debian-12 --image-project debian-cloud --boot-disk-size 30GB --address abada-demo-ip --tags abada-web --metadata-from-file startup-script=deployment/gcp/startup.sh --metadata abada-domain=demo.example.org,abada-acme-email=ops@example.org,abada-version=1.0.0-rc.7

Then connect to the VM and run sudo /opt/abada/release/abada-platform up server. The full procedure, including the static address, firewall rule, DNS, backups and upgrades, is in the GCP operations guide.

  • Model spend. Every started instance calls the model. Use a provider key with a spending cap; ABADA_AGENT_MAX_TASKS=2 limits concurrency.
  • Shared accounts. Anyone with bob’s password can start and complete work. Change ABADA_REVIEWER_PASSWORD and rerun up server to rotate it, or set ABADA_REVIEWER_ENABLED=false to disable the account.
  • Rehearsals. Set ABADA_ACME_CA_SERVER to https://acme-staging-v02.api.letsencrypt.org/directory to avoid Let’s Encrypt rate limits. Browsers do not trust staging certificates.

Stop without deleting data:

Terminal window
./release/abada-platform down server