Skip to main content
Version: v1.4.x

Change AI Virtual Machine Credentials

The built-in templates create a user named pai with a well-known password, so that you can sign in the first time. Replace that credential before you put anything important on the virtual machine.

Credentials live inside the guest operating system. PaletteAI does not manage them, and it does not reset them. Everything on this page is done inside the virtual machine, except for the first-boot setup in Apply Credentials at First Boot, which is set when you create the virtual machine.

The commands below differ between the two built-in templates in a few places. Select your guest operating system, and the choice stays with you for the rest of this page.

Before You Begin​

warning

The built-in templates expire the pai password, so the first sign-in forces you to set a new one and pai stops working from that point. Keep the new password before you disconnect, and connect over the serial console first if you are unsure, so you have a way back in.

Sign in to the virtual machine before you start. Refer to Access an AI Virtual Machine.

Change the Password​

As the pai user, run:

passwd

To set the password for a different user, run sudo passwd <username>.

This works the same on both built-in templates, and the change persists across a stop and start, because cloud-init runs only at first boot and does not put the original password back.

Add or Replace SSH Keys​

Create the directory if it is missing, append the public key, and lock down the permissions:

mkdir --parents ~/.ssh
chmod 700 ~/.ssh
echo '<public-key>' >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys

Replace the contents of ~/.ssh/authorized_keys instead of appending to remove a key you no longer want.

To turn password sign-in off once key sign-in works, set PasswordAuthentication no in /etc/ssh/sshd_config and restart the SSH service:

sudo systemctl restart ssh

Create a Different User​

useradd is used here rather than adduser, because the two images ship different commands under that second name. On Ubuntu, adduser is an interactive script that sets a password as it runs. On Fedora, it is useradd, which does not prompt. The commands below behave the same on both.

Create the user with a home directory, set a password, and grant administrative rights:

sudo useradd --create-home --shell /bin/bash <username>
sudo passwd <username>
sudo usermod --append --groups sudo <username>

Then add that user's SSH key to its own authorized_keys, as described in Add or Replace SSH Keys.

Apply Credentials at First Boot​

To have the virtual machine come up with its own user and password from the start, set cloud-init user data when you create it. In the Console, add it on the Customizations step. For the declarative path, it goes in the manifest that status.renderedVirtualMachine reports and that you write back to spec.virtualMachine.

This user data applies to both built-in templates. It creates one user with administrative rights, an SSH key, and a password that must be changed at first sign-in:

#cloud-config
users:
- default
- name: <username>
lock_passwd: false
sudo: ALL=(ALL) NOPASSWD:ALL
shell: /bin/bash
ssh_authorized_keys:
- <public-key>
ssh_pwauth: true
chpasswd:
expire: true
users:
- name: <username>
type: text
password: <password>

expire: true forces a password change at first sign-in, which is the same behavior the built-in templates set for their pai user. Drop the chpasswd block and the ssh_pwauth line to allow key sign-in only.

This is the better option for a virtual machine you create repeatedly, because the credential is in place from first boot and never relies on the shared default. It does not help an existing virtual machine, since cloud-init runs only once, at first boot.

Next Steps​