====== Deploy and activate ======
This is the short deployment path. Read the [[https://github.com/01ax/binarylane-scoped-api-proxy|repository README]] and [[binarylane-solutions:scoped-api-proxy:operations|security notes]] first.
===== Prerequisites =====
* A BinaryLane API token.
* An Ubuntu 24.04 VPS. ''std-1vcpu'' or larger is recommended.
* SSH access to the VPS.
* A DNS name for public HTTPS, or a VPC, VPN, bastion, or SSH tunnel for private access.
**Warning:** Do not paste the BinaryLane API token into cloud-init. The activation script asks for it after first boot and stores it in ''/opt/bl-proxy/.env'' with root-only permissions.
===== 1. Create the VPS =====
Paste the following into the cloud-init or user-data field when creating the VPS:
#include
https://raw.githubusercontent.com/01ax/binarylane-scoped-api-proxy/345182cc82741b702e9eaa792c34052bf9454b72/generated/bl-scoped-gateway-cloud-init.yaml
Cloud-init downloads the reviewed payload at first boot and processes it as though it had been pasted directly. The URL is pinned to a specific commit so repeated deployments use the same configuration. The VPS needs outbound HTTPS access to ''raw.githubusercontent.com'' during first boot.
You can [[https://github.com/01ax/binarylane-scoped-api-proxy/blob/main/generated/bl-scoped-gateway-cloud-init.include.yaml|open the copyable include file]] or [[https://github.com/01ax/binarylane-scoped-api-proxy/blob/main/generated/bl-scoped-gateway-cloud-init.yaml|review the complete payload]] before deploying. The include is only read at first boot; it does not update an existing VPS if the repository changes.
The payload installs the project under ''/opt/bl-proxy'' and pulls the container images. It does not start the public proxy listener or contain your API token.
Wait for cloud-init to finish, then connect over SSH. You can check cloud-init with:
sudo cloud-init status --wait
===== 2. Activate the gateway =====
sudo /opt/bl-proxy/scripts/activate.sh
The script asks for the BinaryLane API token, access mode, and initial users.
Choose **public HTTPS** only after a DNS ''A'' record points to the VPS. Caddy will obtain and renew the certificate. Choose **private HTTP** only when traffic is protected by a VPC, VPN, bastion, or SSH tunnel; never expose plain HTTP directly to the internet.
===== 3. Verify the result =====
sudo cat /opt/bl-proxy/DEPLOYMENT-NOTES.txt
sudo /opt/bl-proxy/scripts/status.sh
Confirm that ports 9080, 9180, and 2379 are not reachable externally. Only SSH from trusted addresses and ports 80/443 where needed should be exposed.
Continue with [[binarylane-solutions:scoped-api-proxy:roles|Users, roles, and JWTs]].