# How to operate a running Quake AI VM

Source: https://docs.quake.ai/docs/compute/how-to/operate-running-vm
Markdown: https://docs.quake.ai/docs/compute/how-to/operate-running-vm.md

---

# How to operate a running Quake AI VM

Use these procedures to connect over SSH, rotate access, attach storage, check resource usage, transfer files, and recover access to a running VM.



Quake AI Console and CLI commands change control-plane resources. Commands for file transfer, key rotation, storage formatting, and resource inspection run inside the guest OS or from your workstation over SSH.



<PrerequisiteBlock methods={["console", "cli"]}>

- A running Linux or Windows instance
- An SSH key pair or password configured for access
- For private-network instances, a [floating IP](/docs/network/how-to/associate-floating-ip) or VPN path to reach the VM

</PrerequisiteBlock>

## Connect to the VM

For a Linux VM, connect over SSH with your key pair. If SSH is unavailable, use the web console.

**Linux (SSH):**

```bash
ssh -i ~/.ssh/KEY_FILE deploy@VM_ADDRESS
```

Replace `KEY_FILE` with your private key, `deploy` with your login user, and `VM_ADDRESS` with the instance floating IP or reachable private IP.

**Recovery (web console):** follow [How to use the virtual machine console](/docs/compute/how-to/use-vm-console).

**Password login:** set or reset a password with [How to set a password on a virtual machine instance](/docs/compute/how-to/create-password). Use password access for break-glass recovery and keys for routine access.

## Manage SSH keys and rotate access

Quake AI injects the selected OpenStack key pair when it creates an instance. After launch, manage the instance user's keys in the guest `authorized_keys` file.

**Add a new public key to an existing user:**

```bash
echo 'ssh-ed25519 AAAA... comment' >> ~/.ssh/authorized_keys
chmod 600 ~/.ssh/authorized_keys
```

**Remove a compromised key:** edit `~/.ssh/authorized_keys` and delete the line for the old key.

**Register a new key pair for future instances:**

<MethodTabs>
<Method label="Console">

1. Open **Identity** > **Key Pairs**.
2. Select **Create Key Pair**, name it, and download the private key.

</Method>
<Method label="CLI">

```bash
openstack keypair create --public-key ~/.ssh/id_ed25519.pub NEW_KEY_NAME
openstack keypair list
```

</Method>
</MethodTabs>

Existing instances continue using their injected keys until you update `authorized_keys` in the guest.

## Attach and use a block volume

Attach persistent storage through the control plane, then format and mount the device in the guest.

<MethodTabs>
<Method label="Console">

1. Open **Storage** > **Volumes** and confirm the volume status is **Available** (or create one with [How to create a volume](/docs/block/how-to/create-volume)).
2. On the volume row, open the **Volume action** icon dropdown and select **Attach**.
3. Choose the target instance and confirm.

</Method>
<Method label="CLI">

```bash
openstack server add volume INSTANCE_NAME VOLUME_NAME
openstack volume show VOLUME_NAME -c attachments
```

</Method>
</MethodTabs>

Inside the instance, locate the new block device and mount it:



`mkfs` erases data on the selected device. Run `lsblk -f`, identify the device that matches the new volume, and replace `/dev/sdb` in the examples before you run `mkfs`.






```bash
lsblk -f
sudo mkfs.ext4 /dev/sdb
sudo mkdir -p /mnt/data
echo '/dev/sdb /mnt/data ext4 defaults,nofail 0 2' | sudo tee -a /etc/fstab
sudo mount -a
df -h /mnt/data
```

Replace `/dev/sdb` with the device name `lsblk` shows for your attachment.




```bash
lsblk -f
sudo mkfs.xfs /dev/sdb
sudo mkdir -p /mnt/data
echo '/dev/sdb /mnt/data xfs defaults,nofail 0 0' | sudo tee -a /etc/fstab
sudo mount -a
df -h /mnt/data
```




See [How to create a volume](/docs/block/how-to/create-volume) for attach details and [How to extend a volume](/docs/block/how-to/extend-volume) when you outgrow capacity.

## Check resource usage

**In the guest:**

```bash
top -bn1 | head -20
free -m
df -h
iostat -x 1 3 2>/dev/null || true
```

**In the control plane:** open **Compute** > **Instances**, select your instance, and review its status, flavor, addresses, and attached volumes. For CPU, memory, and disk time series, use in-guest tools or your monitoring stack.

## Transfer files

Copy files over SSH with `scp` or `rsync`:

```bash
scp -i ~/.ssh/KEY_FILE ./app.tar.gz deploy@VM_ADDRESS:/tmp/
rsync -avz -e "ssh -i ~/.ssh/KEY_FILE" ./config/ deploy@VM_ADDRESS:/etc/myapp/
```

These commands use the same SSH path as interactive login.

## Recover access when SSH fails

1. Open the [web console](/docs/compute/how-to/use-vm-console) and log in with a password or recovery user.
2. Fix `sshd` configuration, restore `authorized_keys`, or repair the host firewall.
3. If you did not configure password login, set one with [How to set a password on a virtual machine instance](/docs/compute/how-to/create-password), use the console to log in, then repair SSH keys.

## Related documentation

- [How to provision a VM for production](/docs/compute/how-to/provision-production-vm): launch workflow that precedes ongoing operations
- [How to patch and update a Quake AI VM](/docs/compute/how-to/patch-and-update-vm): OS updates after the VM is running
- [How to maintain a Quake AI VM over its lifetime](/docs/compute/how-to/maintain-vm): resize, disk hygiene, and decommissioning
