DigitalOcean ephemeral test VM cheat sheet

This guide is a quick reference for creating temporary DigitalOcean Droplets with doctl, protecting them with Cloud Firewalls through tags, configuring them with Ansible, and destroying them after testing.

The workflow is useful for short-lived lab VMs for networking, proxy, VPN, DNS, Docker, or troubleshooting tests.

Install doctl

On Ubuntu or Debian:

sudo snap install doctl

Confirm the installation:

doctl version

Authenticate doctl

Create a DigitalOcean API token, then initialize local authentication:

doctl auth init

Confirm the account can be reached:

doctl account get

SSH keys

View the local public key:

cat ~/.ssh/id_ed25519.pub

Import the SSH key into DigitalOcean:

doctl compute ssh-key import diogo-laptop --public-key-file ~/.ssh/id_ed25519.pub

List registered SSH keys:

doctl compute ssh-key list

Example output:

ID          Name              FingerPrint
12345678    diogo-laptop      aa:bb:cc:dd:...

Use the key ID with --ssh-keys when creating a Droplet:

--ssh-keys 12345678

Regions

List available regions:

doctl compute region list

Example region:

lon1

Droplet sizes

List available Droplet sizes:

doctl compute size list

For a simple temporary VM, use a small size such as:

s-1vcpu-1gb

Images

List public Ubuntu images:

doctl compute image list-distribution --public | grep Ubuntu

Example image:

ubuntu-24-04-x64

Tags

Create a tag:

doctl compute tag create ephemeral-test

List tags:

doctl compute tag list

The recommended pattern is to attach the Cloud Firewall to a tag:

ephemeral-test

Any Droplet created with that tag will automatically receive the firewall rules.

Create a Droplet

Example:

doctl compute droplet create proxytest \
  --image ubuntu-24-04-x64 \
  --size s-1vcpu-1gb \
  --region lon1 \
  --ssh-keys 12345678 \
  --tag-names ephemeral-test

Replace 12345678 with the real SSH key ID.

List Droplets

doctl compute droplet list

Example output:

ID           Name        Public IPv4
456789123    proxytest   203.0.113.10

Get Droplet information

By name:

doctl compute droplet get proxytest

By ID:

doctl compute droplet get 456789123

Connect with SSH

ssh [email protected]

Cloud Firewall

DigitalOcean Cloud Firewalls do not have an additional cost and can remain in the account even when no Droplets are attached.

For temporary VMs, apply the firewall through a tag instead of attaching it manually to each Droplet.

List Cloud Firewalls

doctl compute firewall list

Get firewall details

doctl compute firewall get <FIREWALL_ID>

Manually attach a Droplet to a firewall

This is not required when using tags, but can be useful for one-off cases:

doctl compute firewall add-droplets <FIREWALL_ID> --droplet-ids <DROPLET_ID>

Example:

doctl compute firewall add-droplets 8a6c1234-abcd-4567-8901-123456789abc --droplet-ids 456789123

Configure the Cloud Firewall once and apply it to this tag:

ephemeral-test

Recommended rules:

Inbound:
TCP/22 <- only from an authorized public source IP
 
Outbound:
ALLOW ALL

Then any Droplet created with this option is automatically covered by the firewall:

--tag-names ephemeral-test

Configure with Ansible

After the Droplet is created, prepare it automatically with Ansible:

ansible-playbook -i "203.0.113.10," -u root cloud-test.yml

A playbook for these temporary VMs might install:

Docker
Docker Compose Plugin
proxychains4
tcpdump
curl
wget
dig
traceroute
netcat
jq
git
iperf3

Destroy the Droplet

By name:

doctl compute droplet delete proxytest --force

By ID:

doctl compute droplet delete 456789123 --force

The Cloud Firewall and tag remain available for reuse.

doctl
  |
  +-- Create Droplet
  |     |
  |     +-- SSH key
  |     +-- tag: ephemeral-test
  |            |
  |            +-- Cloud Firewall applied automatically
  |
  +-- Ansible
  |     |
  |     +-- Docker
  |     +-- proxychains
  |     +-- network tools
  |
  +-- Run tests
  |
  +-- Destroy Droplet

Typical command flow:

doctl compute droplet create proxytest \
  --image ubuntu-24-04-x64 \
  --size s-1vcpu-1gb \
  --region lon1 \
  --ssh-keys 12345678 \
  --tag-names ephemeral-test
 
doctl compute droplet list
 
ansible-playbook -i "203.0.113.10," -u root cloud-test.yml
 
ssh [email protected]
 
doctl compute droplet delete proxytest --force

Future script idea

The workflow can be automated with a script such as:

./spawn-test-vm.sh proxytest

The script could:

  1. Create the Droplet.
  2. Apply the ephemeral-test tag.
  3. Wait for the public IP address.
  4. Wait for SSH to become available.
  5. Run the Ansible playbook.
  6. Print the IP address and SSH command.

Then destroy the VM when testing is complete:

./destroy-test-vm.sh proxytest