Skip to content

How to Reset the Password or SSH Key on a Linux based VM in Quake AI

Troubleshooting · Updated Jun 2026

Coming from another cloud?

▸AWS·Amazon Machine Images (AMIs)

Amazon Machine Images (AMIs)high

  • Managed via EC2 APIs, not Glance.
  • Region-specific with cross-region copy.
  • Marketplace AMIs may charge hourly fees.
  • Includes block device mapping in AMI.
AWS docs ↗
▸Azure·Compute Gallery image definitions and versions

Azure Compute Gallery image definitions and versionshigh

  • Organized in galleries with image definitions and versioned images (Microsoft.Compute/galleries/images/versions), more structured than flat Glance images.
  • Supports global replication to regions with replicas (up to 100), ZRS storage, unlike OpenStack's store-only model.
  • Sharing via RBAC, community galleries, or direct share; requires gallery setup vs simple OpenStack image sharing.
  • New features like Trusted Launch only in Gallery, legacy managed images deprecated.
Azure docs ↗
▸DigitalOcean·Personal Access Tokens

Personal Access Tokens (PATs) and OAuth2 applicationshigh

  • DigitalOcean PATs are account-scoped (access all resources across all projects for that account) with a choice of read or read/write scope. OpenStack application credentials are project-scoped and tied to a specific set of roles.
  • DO supports OAuth2 for third-party app authorization (apps request access on behalf of a user). OpenStack Keystone supports OAuth1.0 for delegated token issuance; full OAuth2 support depends on the Keystone deployment.
  • DO PATs can be set to expire (custom expiry date) or be non-expiring. Keystone token TTL is server-configured, not per-credential.
  • DO does not support service accounts independent of a user identity. OpenStack application credentials survive user password changes and can be restricted to specific API operations via access rules.
DigitalOcean docs ↗
▸Google Cloud·Machine Images (full VM state capture)

OS imageshigh

  • Public images shareable across projects (e.g. debian-cloud); OpenStack typically tenant-private.
  • Image families point to latest version; no OpenStack equivalent.
  • Custom images stored in Cloud Storage with licensing fees for premium OS.
Google Cloud docs ↗
▸Hetzner·API Token

API Tokens (project-scoped Bearer tokens)high

  • Hetzner API tokens are project-scoped: each token is valid only for the project it was created in and must be separately generated per project. OpenStack Keystone application credentials are user-scoped and can be used across projects when the user has appropriate roles.
  • Hetzner has no OAuth2/OIDC integration for API access; all programmatic access requires a static bearer token. Keystone supports OIDC federation, LDAP backends, and federated identity (SAML2).
  • Hetzner tokens have no built-in expiry and must be manually rotated; there is no token TTL or refresh concept. Keystone tokens have configurable TTLs (default 1 hour) and support re-authentication.
  • Hetzner tokens are either read-only or read-write with no fine-grained scope. OpenStack roles (admin, member, reader) provide service-level access control per project.
Hetzner docs ↗

How to Reset the Password or SSH Key on a Linux based VM in Quake AI

Quake AI does not have special access to reset a user's password or SSH key. However, since a VM behaves like a normal server, standard processes can be used to perform a password reset if such a process exists for your operating system.

This guide presents an example using Ubuntu 24.04, but the same process applies to most Linux distributions, and also for similar operating systems such as BSD-based derivatives.


Before you begin#

Steps to reset a password or SSH key#

1. Log in to the console#

Open the console for your VM from the Quake AI dashboard.

Open Console Image


2. Prepare your console window#

Resize your browser window so you can access the "Send CtrlAltDel" button in the top-right corner.

Click inside the black console window so that your keystrokes register inside the VM instead of your local computer.

Console Window Image


3. Reboot and enter GRUB#

Click "Send CtrlAltDel". Immediately click inside the console window and press ESC several times.

Because the VM reboots fast, act during the boot window. You should see the following GNU GRUB window. If instead the system continues to boot, allow the VM to boot fully, then repeat this step until you see the GRUB prompt after pressing the ESC key several times.

GRUB Boot menu#

4. Edit the boot entry#

If you see the GNU GRUB boot menu, use the arrow keys to select the default boot entry (Ubuntu on the standard images).

Press e to edit it.

GRUB Edit Entry


5. Add single-user mode#

Scroll to the line that begins with linux.

At the end of the line, add the word single

GRUB Edit Entry with the word single added


6. Boot into maintenance mode#

Press Ctrl+X to boot with the modified entry.

The system begins to boot, and you should eventually see:

bash
Press Enter for Maintenance

Press Enter, and you get a root shell prompt.

Maintenance mode shell


7. Reset a password#

At the prompt, type:

bash
passwd ubuntu

This resets the password for the ubuntu user.

You may also reset the password for root or any other user as needed.

Password reset


8. Exit maintenance mode#

Type:

bash
exit

Your system should now continue booting to the normal login console.


9. Access with password or SSH#

  • If you normally use password-based access (not recommended), you can now log in with the new password using your normal processes.
  • If you are using SSH key-based access (preferred), you will need to continue passed this step to also update your SSH key configuration.

Console Login


10. Reset SSH key access#

SSH keys are stored in:

bash
~/.ssh/authorized_keys

To update them:

  1. First, log in with your new password via SSH.
  2. Edit the authorized_keys file to add your new SSH key.

⚠️ Since the web console does not allow cut-and-paste, this step is easiest to complete over an SSH session.

If your system is not configured to allow password login over SSH, you will need to temporarily enable it. For the Quake AI Ubuntu image, follow the instructions below. For other distributions the file location, etc. may be slightly different.:

  1. Edit:

    bash
    /etc/ssh/sshd_config.d/60-cloudimg-settings.conf

    Set:

    bash
    PasswordAuthentication yes
  2. Restart SSH:

    bash
    sudo systemctl restart ssh

11. Revert temporary changes#

After you confirm SSH key access is restored:

  1. Revert the SSH configuration change (PasswordAuthentication no).

  2. Optionally remove the password you set earlier by running:

    bash
    sudo passwd -d ubuntu

Troubleshooting#

GRUB does not appear#

  • Confirm you completed the GRUB timeout prerequisite in Before you begin if this is your first recovery attempt on the Quake AI Ubuntu cloud image.
  • If the console does not capture your key presses, click inside the console window immediately after you select Send CtrlAltDel.

System boots without maintenance prompt#

  • Double-check that you edited the correct linux line in GRUB.
  • Ensure the word single was added at the end of the line.

SSH keys get overwritten after reboot#

The Quake AI Ubuntu cloud image's cloud-init configuration (/etc/cloud/cloud.cfg) does not overwrite ~/.ssh/authorized_keys on reboot. If you observe this behavior on a non-Quake AI image, consult that image's cloud-init documentation (/etc/cloud/cloud.cfg and /etc/cloud/cloud.cfg.d/) and the upstream cloud-init users / ssh_authorized_keys reference. Do not edit /etc/cloud/cloud.cfg directly on a vendor-managed image; use a drop-in under /etc/cloud/cloud.cfg.d/.

Cannot edit files in console#

  • The web console does not allow copy-paste. If you need to add long SSH keys, use password login temporarily, then update your key via an SSH session.

Summary#

By following these steps, you can recover access to your Quake AI VM when password or SSH key access is lost. The process leverages standard Linux recovery workflows, meaning it works the same way as it would on a physical linux server.

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

For the full policy, see Usage Guidelines.

Last validated: 04.06.2026

Before this

Quick answers

Was this page helpful?