# On Azure

At the end, you have a box on Microsoft Azure, a virtual machine (VM) in Azure's words, with Docker on it, and a Terminal on it from your laptop.

## At a glance

**Time:** 15 minutes, then [Any Linux computer with Docker](any-box.md).

**What you need:**

- An Azure account with a subscription you can create resources in
- About 30 to 40 dollars a month while the box runs

**Steps:**

1. Rent the box
2. Let only you in
3. Connect to it
4. Install Docker

## Steps

1. **Sign in to the Azure portal, type Virtual machines in the search bar at the top and open it.**
2. **Press Create, then Azure virtual machine**, and fill it in:
   - **Resource group:** press **Create new** and name it `loopgate`. It is a folder for everything this box uses.
   - **Virtual machine name:** `loopgate-runner`.
   - **Region:** the one nearest your team.
   - **Image:** **Ubuntu Server 24.04 LTS - x64 Gen2**. The "x64" part matters.
   - **Size:** press **See all sizes** and choose **B2s** (2 processors and 4 GiB of memory).
   - **Authentication type:** **SSH public key**. **Username:** `azureuser`. **SSH public key source:** **Generate new key pair**. **Key pair name:** `loopgate`.
   - **Public inbound ports:** **Allow selected ports**, then **SSH (22)** only.
   - **Disks** tab: check that **OS disk size** is at least **30 GiB**.
3. **Press Review + create, then Create, then Download private key and create resource.** Your browser downloads `loopgate.pem`, the key to the box; keep it safe.

   You should see: "Your deployment is complete" after a minute or two.

4. **Press Go to resource and copy the Public IP address**, four numbers with dots such as `20.71.45.67`.
5. **Open Networking → Network settings and the rule for port 22 (SSH).**
6. **Change Source from Any to My IP address and press Save.** Now only your laptop's current address can knock.
7. **On your laptop, in Terminal, lock the key file** so only you can read it. SSH refuses a key that others can read.

   ```sh
   chmod 400 ~/Downloads/loopgate.pem
   ```

8. **Connect**, with the address from step 4 in place of `<address>`.

   ```sh
   ssh -i ~/Downloads/loopgate.pem azureuser@<address>
   ```

   You should see: a question about the box's fingerprint. Type `yes` and press Enter. Then a welcome message and a prompt that starts `azureuser@`.

9. **Install Docker with Docker's own script.**

   ```sh
   curl -fsSL https://get.docker.com | sudo sh
   ```

   You should see: a few minutes of output ending with a note about running Docker as a non-root user.

10. **Let your user run Docker without `sudo`, then leave.**

    ```sh
    sudo usermod -aG docker $USER && exit
    ```

11. **Connect again with the `ssh` command from step 8**, so the change takes hold.

## Check

Docker answers without `sudo` with `Docker Compose version v2.` followed by more numbers:

```sh
docker compose version
```

## Next

Your box is ready. Paste the command from the portal: [Any Linux computer with Docker](any-box.md).

## If something is off

- **SSH stops connecting one day.** Your address at home or at the office changed. Set the port 22 rule to **My IP address** again (step 6).
- **SSH says the key's permissions are too open.** Run step 7 again.
- **Docker says permission denied.** Leave and connect again (step 11).

## Doing it by hand

Once Docker answers, [By hand](by-hand.md) sets the runner up from files instead of the portal's line.
