Skip to main content

Logging in

Applies to SynapseOS builds from 2026-10-09 (20261009-141152 and later). See What changed.

Root, with a key, over SSH. A password is for the console.

The first credential​

An image ships with the root account locked and no password at all: a credential baked into every unit would be a secret shared by every customer. Access is provisioned per unit instead, in one of two ways.

  • Delivered with the unit. A physical appliance, or a VM Gen0Sec deployed for you, arrives with an SSH key already installed for root, or with a console password. Use what came with the unit.

  • Your own cloud-init seed. A VM you start from a SynapseOS image reads a NoCloud seed on first boot: a FAT-formatted volume labelled CIDATA holding meta-data and user-data. The key it installs is what you log in with.

    user-data
    #cloud-config
    disable_root: false
    ssh_authorized_keys:
    - ssh-ed25519 AAAA... [email protected]
    meta-data
    instance-id: appliance-01
    local-hostname: appliance-01

    The seed delivers credentials and, through local-hostname, the unit's name. Networking on the appliance is not managed by cloud-init; see Configuring the appliance.

SSH​

ssh root@<address>

As shipped, root logs in with a key only (PermitRootLogin prohibit-password) and password authentication is off for every account. A unit can be delivered with password SSH turned on instead, by a drop-in under /etc/ssh/sshd_config.d/; sshd -T | grep -i passwordauthentication shows which applies, and removing the drop-in restores key-only. SSH on port 22 is the only service the base firewall accepts from outside by default.

To add a key of your own, append it to /root/.ssh/authorized_keys. It lives on the writable root filesystem and survives updates.

The console​

A password works on the serial console and nowhere else. If no password came with the unit, set one once you are in over SSH:

passwd root

That also unlocks the account for console login; SSH stays key-only.

The console is the only way in when the network is misconfigured, so it is worth having a password set before you change addressing. Where the console is depends on the unit: a Cerebrum Max's BMC, a Cerebrum Edge's serial port over USB, a server's BMC, or a VM's serial port. See Platforms and, for the cable and the terminal settings, Serial console.

Naming the unit​

hostnamectl set-hostname appliance-01

The name is written to /etc/hostname and kept across updates.

Knowing what you are running​

/etc/os-release and the login banner name the build the unit was delivered with:

FieldMeaning
VERSIONThe delivered image's build stamp, as shown in the login banner
SYNAPSEOS_RECIPEWhich platform build this is
SYNAPSEOS_BUILD_OPTIONSThe image options it was built with, such as hardened and ab

Updates replace the system, not /etc, so neither changes afterwards. The build that is running is in synapseos-ab-update status, beside the slot marked <- running, and in /usr/lib/os-release, which belongs to the running system. Use those when reporting a unit. See Updating.