DigitalOcean ephemeral test VM cheat sheet
This guide is a quick reference for creating temporary DigitalOcean Droplets with doctl, protecting them with Cloud Firewalls through tags, configuring them with Ansible, and destroying them after testing.
The workflow is useful for short-lived lab VMs for networking, proxy, VPN, DNS, Docker, or troubleshooting tests.
Install doctl
On Ubuntu or Debian:
sudo snap install doctlConfirm the installation:
doctl versionAuthenticate doctl
Create a DigitalOcean API token, then initialize local authentication:
doctl auth initConfirm the account can be reached:
doctl account getSSH keys
View the local public key:
cat ~/.ssh/id_ed25519.pubImport the SSH key into DigitalOcean:
doctl compute ssh-key import diogo-laptop --public-key-file ~/.ssh/id_ed25519.pubList registered SSH keys:
doctl compute ssh-key listExample output:
ID Name FingerPrint
12345678 diogo-laptop aa:bb:cc:dd:...Use the key ID with --ssh-keys when creating a Droplet:
--ssh-keys 12345678Regions
List available regions:
doctl compute region listExample region:
lon1Droplet sizes
List available Droplet sizes:
doctl compute size listFor a simple temporary VM, use a small size such as:
s-1vcpu-1gbImages
List public Ubuntu images:
doctl compute image list-distribution --public | grep UbuntuExample image:
ubuntu-24-04-x64Tags
Create a tag:
doctl compute tag create ephemeral-testList tags:
doctl compute tag listThe recommended pattern is to attach the Cloud Firewall to a tag:
ephemeral-testAny Droplet created with that tag will automatically receive the firewall rules.
Create a Droplet
Example:
doctl compute droplet create proxytest \
--image ubuntu-24-04-x64 \
--size s-1vcpu-1gb \
--region lon1 \
--ssh-keys 12345678 \
--tag-names ephemeral-testReplace 12345678 with the real SSH key ID.
List Droplets
doctl compute droplet listExample output:
ID Name Public IPv4
456789123 proxytest 203.0.113.10Get Droplet information
By name:
doctl compute droplet get proxytestBy ID:
doctl compute droplet get 456789123Connect with SSH
ssh [email protected]Cloud Firewall
DigitalOcean Cloud Firewalls do not have an additional cost and can remain in the account even when no Droplets are attached.
For temporary VMs, apply the firewall through a tag instead of attaching it manually to each Droplet.
List Cloud Firewalls
doctl compute firewall listGet firewall details
doctl compute firewall get <FIREWALL_ID>Manually attach a Droplet to a firewall
This is not required when using tags, but can be useful for one-off cases:
doctl compute firewall add-droplets <FIREWALL_ID> --droplet-ids <DROPLET_ID>Example:
doctl compute firewall add-droplets 8a6c1234-abcd-4567-8901-123456789abc --droplet-ids 456789123Recommended firewall and tag strategy
Configure the Cloud Firewall once and apply it to this tag:
ephemeral-testRecommended rules:
Inbound:
TCP/22 <- only from an authorized public source IP
Outbound:
ALLOW ALLThen any Droplet created with this option is automatically covered by the firewall:
--tag-names ephemeral-testConfigure with Ansible
After the Droplet is created, prepare it automatically with Ansible:
ansible-playbook -i "203.0.113.10," -u root cloud-test.ymlA playbook for these temporary VMs might install:
Docker
Docker Compose Plugin
proxychains4
tcpdump
curl
wget
dig
traceroute
netcat
jq
git
iperf3Destroy the Droplet
By name:
doctl compute droplet delete proxytest --forceBy ID:
doctl compute droplet delete 456789123 --forceThe Cloud Firewall and tag remain available for reuse.
Recommended workflow
doctl
|
+-- Create Droplet
| |
| +-- SSH key
| +-- tag: ephemeral-test
| |
| +-- Cloud Firewall applied automatically
|
+-- Ansible
| |
| +-- Docker
| +-- proxychains
| +-- network tools
|
+-- Run tests
|
+-- Destroy DropletTypical command flow:
doctl compute droplet create proxytest \
--image ubuntu-24-04-x64 \
--size s-1vcpu-1gb \
--region lon1 \
--ssh-keys 12345678 \
--tag-names ephemeral-test
doctl compute droplet list
ansible-playbook -i "203.0.113.10," -u root cloud-test.yml
ssh [email protected]
doctl compute droplet delete proxytest --forceFuture script idea
The workflow can be automated with a script such as:
./spawn-test-vm.sh proxytestThe script could:
- Create the Droplet.
- Apply the
ephemeral-testtag. - Wait for the public IP address.
- Wait for SSH to become available.
- Run the Ansible playbook.
- Print the IP address and SSH command.
Then destroy the VM when testing is complete:
./destroy-test-vm.sh proxytest