Prerequisites
- An account on the target cloud with permission to launch VM instances (no special IAM roles are required by this product unless stated below — IAM required: none).
- An SSH key pair registered in the target cloud (all access is key-only; password SSH is disabled).
- Instance size ≥ 4 vCPU (pricing floor; 8 vCPU recommended).
- No internet access or external dependency is required at deploy time — the image is self-contained.
Google Cloud
- Deploy from the Google Cloud Marketplace listing (or its deployment package): at least 4 vCPU and 16 GB RAM (default n2-standard-8, 50 GB balanced boot disk). Leave the tcp:6379 firewall toggle off for now.
Expected result The VM DEPLOYMENT-vm is RUNNING and gcloud compute ssh connects. - On the VM, read the password and ping the server (First login, below).
Expected result valkey-cli PING returns PONG with the password and NOAUTH without it. - For clients in your VPC: add the VM's internal IP to bind in /etc/valkey/valkey.conf, sudo systemctl restart valkey, then allow tcp:6379 from your client range only (deployment toggle or your own firewall rule).
Expected result A client in that range connects with the password; nothing else can.
Validate
VALKEYCLI_AUTH="$(sudo sed -n 's/^VALKEY_PASSWORD=//p' /root/valkey-credentials.txt)" valkey-cli PING → PONG
First boot: valkey-firstboot.service mints the per-VM password into /etc/valkey/auth.conf and /root/valkey-credentials.txt before valkey.service first starts; valkey-verify-firstboot.service then proves against the running server that the password works, that no password and a wrong one are refused, that it runs 9.1.2 and that 6379 is loopback-only, and writes /var/lib/dca-firstboot/valkey.verified.
First login / credentials
- Connect with OS Login: gcloud compute ssh INSTANCE_NAME --zone ZONE --tunnel-through-iap (reading the credential file needs sudo, i.e. the roles/compute.osAdminLogin IAM role).
- Load this VM's password, generated on its first boot: export VALKEYCLI_AUTH="$(sudo sed -n 's/^VALKEY_PASSWORD=//p' /root/valkey-credentials.txt)" — the file is root-only (0600).
- valkey-cli PING returns PONG. Without the password the server answers NOAUTH; 6379 is bound to loopback until you change bind (see Configuration).
Secure it
- Restrict SSH (22) to your own IP range in the cloud firewall/security group.
- Open application ports only per the ports table — closed-by-default is deliberate.
- Volume encryption: use your cloud's native volume encryption (enabled by default on most accounts); the image adds no proprietary encryption layer.
Costs & quotas
Software is billed by the marketplace at the listed rate; infrastructure (VM, storage, egress) is billed
by your cloud at its standard rates. The recommended size fits default service quotas in most accounts —
if you scale out, review your cloud's quota console before launch.
Next: configuration · troubleshooting · security notes
Valkey™ names the open-source software this image packages. Derek Coleman & Associates Inc is not affiliated with or endorsed by the Valkey project.