Legacy Backend VM Deployment
The current backend deployment path is GKE. The old VM nginx/Certbot runtime assets were removed from the backend repo; use Git history only if you need to inspect the former implementation.
The legacy path ran each backend on a dedicated Compute Engine VM with Docker Compose, nginx, Certbot, a static external IP, and a primary DNS record.
When to use this page
Use this page only when:
- You need to understand the older VM deployment flow.
- You are cleaning up legacy VM resources.
- You are investigating an older deployment from Git history.
For the current backend path, use Backend on GKE.
Backend VM setup
- Create a Compute Engine instance.
- Name it
<collaborator>-uow-server. - Allow full access to Google Cloud APIs.
- Reserve a static external IP address.
- Copy the required SSH keys from an existing server.
- Resize the boot disk if needed.
SSH into the VM and install required packages:
sudo apt-get update
sudo apt-get install -y gcc
Create the backend runtime .env file on the VM with database, OAuth, storage, Document AI, and collaborator settings.
Install Docker using the standard Docker installation instructions for the VM operating system.
DNS
In Google Cloud DNS, add an A record:
<collaborator>-server.uow-carbon.org
Point it to the VM static external IP.
If Terraform should manage this VM, keep its definition in legacy_backend_vms, add the collaborator key to enabled_legacy_backend_vms, and import the existing VM resources before applying Terraform:
cd orphaned-wells-ui-server/deployment/terraform
terraform init
terraform workspace select ogrre
bash scripts/import_existing_infrastructure.sh --target-workspace ogrre --backend-vms-only <collaborator>
nginx and Docker Compose
The backend repository no longer carries the legacy nginx configs, Certbot cron entry, or full VM Compose stack. GKE now provides public routing through Ingress and Google-managed certificates. Recover the removed VM assets from Git history only when investigating or temporarily restoring the retired path.
Legacy GitHub Actions
Older VM workflows deployed over SSH to a target VM. They required legacy backend repository secrets such as:
DEPLOY_TARGETSSSH_USERNAME
Prefer GKE workflows for current deployments. Keep any temporary legacy VM recovery isolated and clearly labeled.