How to set up a Garry's Mod server: a step-by-step guide
This guide takes you from nothing to a working Garry's Mod server: choosing an operating system, installing through SteamCMD, loading a Workshop collection, opening ports and the mistakes most often made on first boot. Garry's Mod itself is a light server; what drives the resource requirement is the gamemode and addon list you run, which is where most of this guide lives.
Before you start
- A decision about the gamemode. Sandbox and TTT are light, DarkRP is heavy. That decision sets the hardware directly: a sandbox server with a moderate addon list runs on 4 GB / 2 vCPU, while a DarkRP server carrying more than a hundred addons wants 8 GB / 4 vCPU and 160 GB of storage. We have written separately about how that calculation works: how many vCPUs and how much RAM? To pick those resources one by one and see the monthly total, use the server configurator.
- A Steam Web API key. The server needs it to download your Workshop collection on its own; it is passed on the start line with
-authkey. - An HTTP source for content delivery. If addons are downloaded from the game server itself, first joins take a long time and the download work sits on the server CPU.
1. Operating system
Choose Ubuntu 22.04 LTS or Debian 12. The Garry's Mod dedicated server runs on the Source engine's srcds binary and on the default branch it is compiled as 32-bit; because modern distributions do not install 32-bit libraries, skipping this step makes the process exit without an error.
Before installing, verify what the binary actually needs. Every not found line in the ldd output is a missing library:
ldd ./srcds_linux
dpkg --add-architecture i386
apt update
apt install lib32gcc-s1 lib32stdc++62. Installing through SteamCMD
The server files are downloaded anonymously through SteamCMD; the app ID for the Garry's Mod dedicated server is 4020:
./steamcmd.sh +force_install_dir /home/gmod/server +login anonymous \
+app_update 4020 validate +quitThe thing to watch here is content. A large share of community maps depend on Counter-Strike: Source assets; that content is downloaded as a separate SteamCMD app and mounted through garrysmod/cfg/mount.cfg. If it is left out, the map still loads but parts of the walls turn into the purple-and-black checker texture, and players report it as "the server is broken".
3. Configuration, Workshop and FastDL
Server settings live in garrysmod/cfg/server.cfg: the server name, the RCON password and a server password if you use one. The gamemode, map and collection are given on the start line instead:
./srcds_run -game garrysmod -console -port 27015 \
+maxplayers 32 +gamemode sandbox +map gm_construct \
+host_workshop_collection COLLECTION_ID -authkey STEAM_API_KEYSeparate content delivery with FastDL: the HTTP address you point sv_downloadurl at moves the files a first-time player downloads completely off the server process. With a large addon collection this is the single most effective setting for protecting tick time.
Add addons one at a time, and after each one start the server once and read the console. Because Lua runs on the main thread, a single badly written addon can slow the whole server down; installing twenty together and then hunting for the culprit is the longest possible route.
4. Ports
| Port | Protocol | Purpose |
|---|---|---|
| 27015 | UDP | Game traffic and server list queries |
| 27015 | TCP | RCON (open it to your own IP only) |
RCON is full administration of your server, and opening it to everyone in the firewall is a common and serious mistake. If you host FastDL on the same machine, the web server's port needs to be open too. If you are on Datafex, port management and extra IP requests are handled from the customer panel.
The most common first-boot mistakes
- The 32-bit libraries were never installed. The process appears to start and exits immediately, leaving nothing useful in the log.
- No `-authkey`. The collection is not downloaded; the server starts but players run into missing content.
- No FastDL. First joins take minutes and the download load lands directly on the game process.
- Addons installed in bulk. Tick time drops and finding the culprit means removing them one by one anyway.
- A weak RCON password, or one shipped alongside the config files. That password is the whole server.
- No backups. In gamemodes like DarkRP, player money and inventory are held server-side and the loss cannot be undone. The approach in server backup strategy applies here too.
On the DDoS side
Source-based servers are both a direct target and a reflector in someone else's attack because of the query packets the server list uses: the response to a query is larger than the request itself. Since source addresses can be forged in UDP, blocking IPs does not help; filtering has to happen at the network layer. Details: what is DDoS protection?
On Datafex servers, layered Fexwall DDoS protection is included free on every plan.
Next step
As addon load grows, storage and single-core performance become limiting together, and at that point changing plan is cheaper than deleting addons. We have put the recommended configurations by player count and gamemode on one page: Garry's Mod server plans. If you plan to run several gamemode instances on the same machine, the vCPU steps on the virtual server plans will be your decision point.