Logging in
Applies to SynapseOS builds from 2026-10-09 (20261009-141152 and later). See What changed.
Root, with a key, over SSH. A password is for the console.
The first credential
An image ships with the root account locked and no password at all: a credential baked into every unit would be a secret shared by every customer. Access is provisioned per unit instead, in one of two ways.
-
Delivered with the unit. A physical appliance, or a VM Gen0Sec deployed for you, arrives with an SSH key already installed for root, or with a console password. Use what came with the unit.
-
Your own cloud-init seed. A VM you start from a SynapseOS image reads a NoCloud seed on first boot: a FAT-formatted volume labelled
CIDATAholdingmeta-dataanduser-data. The key it installs is what you log in with.user-data#cloud-configdisable_root: falsessh_authorized_keys:meta-datainstance-id: appliance-01local-hostname: appliance-01The seed delivers credentials and, through
local-hostname, the unit's name. Networking on the appliance is not managed by cloud-init; see Configuring the appliance.
SSH
ssh root@<address>
As shipped, root logs in with a key only (PermitRootLogin prohibit-password) and
password authentication is off for every account. A unit can be delivered with password
SSH turned on instead, by a drop-in under /etc/ssh/sshd_config.d/; sshd -T | grep -i passwordauthentication shows which applies, and removing the drop-in restores key-only.
SSH on port 22 is the only service the base firewall accepts from outside by default.
To add a key of your own, append it to /root/.ssh/authorized_keys. It lives on the
writable root filesystem and survives updates.
The console
A password works on the serial console and nowhere else. If no password came with the unit, set one once you are in over SSH:
passwd root
That also unlocks the account for console login; SSH stays key-only.
The console is the only way in when the network is misconfigured, so it is worth having a password set before you change addressing. Where the console is depends on the unit: a Cerebrum Max's BMC, a Cerebrum Edge's serial port over USB, a server's BMC, or a VM's serial port. See Platforms and, for the cable and the terminal settings, Serial console.
Naming the unit
hostnamectl set-hostname appliance-01
The name is written to /etc/hostname and kept across updates.
Knowing what you are running
/etc/os-release and the login banner name the build the unit was delivered with:
| Field | Meaning |
|---|---|
VERSION | The delivered image's build stamp, as shown in the login banner |
SYNAPSEOS_RECIPE | Which platform build this is |
SYNAPSEOS_BUILD_OPTIONS | The image options it was built with, such as hardened and ab |
Updates replace the system, not /etc, so neither changes afterwards. The build that is
running is in synapseos-ab-update status, beside the slot marked <- running, and
in /usr/lib/os-release, which belongs to the running system. Use those when reporting a
unit. See Updating.