Use one VM per tunnel. Do not add several VMs to a single tunnel.
Costs
Nebius AI Cloud charges you for the following billing items:- Compute virtual machine
- Boot disk attached to the VM
Steps
Create a tunnel
- Web console
- CLI
- In the web console, select the project where you want to create the infrastructure. All resources must be located in the same project.
- Go to Networking → Tunnels.
- Click Create tunnel.
- On the page that opens, set the tunnel name to
my-tunnel. - Click Create tunnel.
Prepare a service account
To authorize the VM in the tunnel, prepare a service account with theapplicationtunnel.agent role. Later, you attach this service account to the VM.
-
Create the service account:
- Web console
- CLI
- In the sidebar, go to Administration → IAM.
- Click Create resource → Service account.
- In the window that opens, set the name to
tunnel-agent-saand select the project. - Click Create and continue.
-
Create a custom group in Identity and Access Management to assign the role to the service account:
- Web console
- CLI
- In the sidebar, go to Administration → IAM.
- Click Create resource → Group.
- In the window that opens, set the group name to
tunnel-agents. In the Scope field, select the project where you create all the resources. - Click Create.
-
Attach the tunnel and grant the
applicationtunnel.agentrole to this group. You can only grant this role by using the CLI.- CLI
-
Get the group ID:
The ID is specified in the
items.metadata.idparameter in the output. -
Get the tunnel ID:
-
Create an access permit in the custom group:
-
Add the service account to the group:
- Web console
- CLI
- Go to Administration → IAM.
- On the Groups tab, find and open the
tunnel-agentsgroup. - Click Add members.
- In the window that opens, add the
tunnel-agent-saservice account. - Once the account is added, close the window.
- The
tunnel-agent-saservice account is specified on the Members tab. - The tunnel and the
applicationtunnel.agentrole are specified on the Access permits tab.
Create a virtual machine
Prepare the VM configuration that includes the JupyterLab image and the tunnel agent. Then, create the VM — the image and agent are deployed on the VM automatically.- Generate an SSH key pair.
-
Prepare the cloud-init configuration file. You’ll attach it to the VM.
In this file, specify two parameters:
users.ssh_authorized_keys: Public SSH key.write_files.content.tunnel_id: ID of the tunnel.
jupyterlab.yaml
This configuration enables the following actions:- Add a username and a public SSH key to the VM.
- Install Docker on the VM.
- Deploy the tunnel agent.
- Authenticate by using the service account attached to the VM.
- Create two Nebius Tunnels services:
jupyterandssh. Use them to connect to the tunnel. - Deploy JupyterLab on the VM.
- Generate a JupyterLab token. With this token, you’ll be able to authenticate to JupyterLab and open it.
-
Create the VM:
- Web console
- CLI
- In the sidebar, go to Compute → Virtual machines.
- Click Create resource → Virtual machine. The creation flow is a step-by-step wizard. The sidebar shows your progress through the configuration sections. To move between sections, click Back and Next.
-
On the Compute step, configure computing resources:
-
In the Platform section, select:
- Without GPUs
- Regular
- Non-GPU AMD Epyc Genoa
-
In the Settings section, set:
- Preset: 8 CPUs - 32 GiB RAM
- Project: The project where you create all resources for the tunnel.
- VM name:
tunnel-jupyter.
-
In the Platform section, select:
- On the Storage step, preserve the Ubuntu 24.04 LTS disk image and the SSD disk type but change the disk size to 50 GiB.
- On the Network step, check the network and subnet. Keep None in the Public IP address field.
-
On the Configuration step, configure access, identity and VM startup settings:
- In the Service account field, select the
tunnel-agent-saservice account. - Enable a custom cloud-init configuration file.
- In the field that appears, paste the contents of the
jupyterlab.yamlfile prepared earlier.
- In the Service account field, select the
- On the Review step, check the full VM configuration. To change a section quickly, click next to the corresponding block. The wizard opens the relevant step with your current settings.
- Click Create.
Open JupyterLab
-
Get the JupyterLab token. To do so, connect to the VM and extract the token from the VM:
In the VM address, specify:
tunnel_masked_ID: Mask of the tunnel ID without theapplicationtunnel-prefix and regional routing code. Contains the last 15 characters of the tunnel ID. For example, forapplicationtunnel-e00abcdef123456789, the masked ID of the tunnel isabcdef123456789.region: Region of the project where you created the resources.
-
Open JupyterLab in the browser by using the following URL:
In the URL, specify the masked ID of the tunnel, the region and the token. The page can take about a minute to open. If you see the message
failed to connect to local serviceinstead, this means that JupyterLab hasn’t started yet. Wait a few moments and try again.
How to delete the created resources
The created VM and its boot disk are chargeable. If you don’t need them, delete the VM, so Nebius AI Cloud doesn’t charge for the resources. The boot disk is deleted automatically when you delete the VM. You can also delete free resources:“Jupyter” and the Jupyter logos are trademarks or registered trademarks of LF Charities, used by Nebius B.V. with permission.