Set up OpenAEON (https://docs.openaeon.ai/install) on this VM. Use the non-interactive and accept-risk flags for openaeon onboarding. Add the supplied auth or token as needed. Configure nginx to forward from the default port 18789 to the root location on the default enabled site config, making sure to enable Websocket support. Pairing is done by "openaeon devices list" and "openaeon device approve <request id>". Make sure the dashboard shows that OpenAEON's health is OK. exe.dev handles forwarding from port 8000 to port 80/443 and HTTPS for us, so the final "reachable" should be <vm-name>.exe.xyz, without port specification.