GCP Marketplace
What you just deployed
One Compute Engine instance running Repave, entirely inside your own project. Nothing phones home, and no credential of ours is on the instance.
First boot takes about 5–10 minutes. Until it finishes the site refuses connections — nginx does not start until the application is healthy. That is expected; you have not mis-deployed anything.
To watch it:
gcloud compute ssh DEPLOYMENT-vm --zone ZONE --project PROJECT \
--command 'sudo journalctl -u repave-firstboot -f'
Logging in over SSH also prints a status banner — "still setting up", "running at …", or a failure naming the step that failed.
Signing in
First boot creates one administrator account and generates its password on the instance. The password is never in the image, never in our hands, and never leaves your project.
# From the instance's guest attributes:
gcloud compute instances get-guest-attributes DEPLOYMENT-vm --zone ZONE \
--project PROJECT --query-path=app-rewrite/
# Or from the credentials file, which is written whether or not guest
# attributes are enabled:
gcloud compute ssh DEPLOYMENT-vm --zone ZONE --project PROJECT \
--command 'sudo cat /root/app-rewrite-admin.txt'
The account is admin@repave.local. Change the password after your first
sign-in, at /account/reset-password.
The certificate warning is expected
Until you point your own domain at the instance, it serves a self-signed certificate generated on first boot for its own IP address. Your browser will warn once. The alternative — plain HTTP — would put that generated password on the wire in clear text at the very first sign-in.
You need a license before the product will do anything
Repave is licensed software. Until a license is imported, every page
redirects to /license. This is deliberate, and it is the one step you cannot
complete on your own.
Request one from support@repave.ai, including:
- the Google Cloud project ID you deployed into
- the deployment name you chose
- the site URL shown on the deployment page
- your organisation name, and a contact for renewal
We issue a signed license file and send it back. Paste it into /license on your
instance and the product unlocks. The first import needs no account, so you can
do it before signing in.
If you are evaluating and do not have a commercial agreement yet, say so in the same message — that is the normal starting point, not a problem.
Accounts are by invitation
A Marketplace instance sits on a public address, so open sign-up is turned off: whoever found the URL first would otherwise get an account.
To add a colleague:
- Sign in as the administrator and create a project.
- Invite their email address from the project's Team page. With email set up (see below), they receive the invitation by email; otherwise copy the invitation link the page shows and send it to them.
- They open the link, choose Create account, and sign up with that address.
You are the administrator
admin@repave.local is this installation's administrator. Open the account menu
(top right) and choose Admin portal to:
- set the API keys every project uses unless it sets its own;
- set up Email, so people can reset a forgotten password and invitations are sent by email;
- manage Users: make someone else an administrator, remove it, disable or re-enable an account, or send a password reset;
- replace the License.
Make at least one colleague an administrator once they have an account, so the installation never depends on a single login. See Admin portal.
An address with no pending invitation is refused. If you would rather run with
open sign-up — on an instance only your network can reach, for example — set
REPAVE_SIGNUP_MODE=open in /opt/app-rewrite/current/.env and restart the
application.
Using your own domain
The instance follows its external IP automatically, so an ephemeral address that changes across a stop/start does not break the site. Once you point a real domain at it, take that over:
# 1. Reserve a static external IP and point your DNS at it.
# 2. Install your certificate.
sudo cp fullchain.pem privkey.pem /opt/app-rewrite/tls/live/app-rewrite/
# 3. Set the URL the application advertises.
sudo sed -i 's|^REPAVE_PUBLIC_URL=.*|REPAVE_PUBLIC_URL=https://repave.example.com|' \
/opt/app-rewrite/current/.env
# 4. Stop first boot managing the address on your behalf.
sudo rm /var/lib/repave/public-url.auto
# 5. Restart the web tier.
sudo docker compose --project-directory /opt/app-rewrite/current \
up -d --force-recreate app nginx
Step 4 matters: while that marker exists, a later boot will overwrite
REPAVE_PUBLIC_URL with the instance's current IP.
Sizing
| Recommended | e2-standard-8 (8 vCPU, 32 GB) |
| Minimum | e2-standard-4 (4 vCPU, 16 GB) |
| Boot disk | 150 GB, 120 GB minimum |
Agent runs are containers alongside the application, its database and its memory service, so a smaller machine type starts fine and then fails on the first real agent job. The disk carries roughly 62 GB of container images before any of your work; the rest is room for your projects, workspaces, database and agent containers.
If a deployment goes wrong
The site never comes up. Log in over SSH and read the banner. A failure names
the step; sudo journalctl -u repave-firstboot has the detail. Setup retries
from the beginning on reboot, and every step is safe to repeat — no secret is
rotated and no password is reset by a retry.
You are locked out of the administrator account. If email is set up (Admin portal → Email), use Forgot password? on the sign-in page. Otherwise, or if the account was disabled or lost its administrator rights, with SSH access:
printf '%s' 'a-new-password' | sudo docker compose \
--project-directory /opt/app-rewrite/current \
run --rm -T app npm run bootstrap-admin -- --reset
This sets a new password for admin@repave.local, makes it an administrator again, and re-enables
it.
Anything else: support@repave.ai, with the output of
sudo journalctl -u repave-firstboot.
Upgrading
Upgrades use the standard Docker Compose upgrade path documented with the release, not a redeploy from Marketplace — redeploying creates a new instance with a new disk and leaves your projects behind.