--- title: Non-root User description: Create a non-root SSH user and give it the access Coolify needs to manage a server. --- # Use a non-root server user Coolify can connect to a server using an account other than `root`. This feature is experimental and still requires the account to run commands with passwordless `sudo`. The user created in this guide can run any command as `root` without entering a password. Use a dedicated account and SSH key only for Coolify. This guide uses `cooluser` as the username. Replace `cooluser` with the username you want to use. --- ## Configure the non-root user ### Sign in as root Connect to the server as `root` using SSH or the server console. Keep this session open until Coolify successfully validates the new account. ### Create the user Run the command for the server's operating system. ```sh useradd --create-home --user-group --shell /bin/bash --password 'NP' cooluser ``` Use this for CentOS, RHEL, Rocky Linux, AlmaLinux, Fedora, Amazon Linux, Oracle Linux, or TencentOS. ```sh useradd --create-home --user-group --shell /bin/bash --password 'NP' cooluser ``` ```sh useradd --create-home --user-group --shell /bin/bash --password 'NP' cooluser ``` ```sh useradd --create-home --user-group --shell /bin/bash --password 'NP' cooluser ``` ```sh adduser -D -s /bin/ash cooluser ``` `--password 'NP'` leaves the account unlocked while keeping password login disabled (`NP` is not a valid hash). A brand-new account otherwise has a locked password (`!` in `/etc/shadow`), and OpenSSH refuses key-based logins to a locked account, so Coolify's server validation fails. Alpine's busybox `adduser` has no equivalent flag, so its account stays locked. Alpine's OpenSSH is built without PAM and still accepts key-based logins, so no change is needed. If your Alpine build uses PAM, unlock the account with `apk add shadow && usermod -p 'NP' cooluser`. Confirm the account exists and is not locked: ```sh id cooluser passwd -S cooluser ``` `id` prints the user's ID and group information. In `passwd -S`, the status field (second column) should be `P`, not `L`. ### Open the Coolify dashboard 1. Select **Keys & Tokens** in the sidebar. 2. Select **Private Keys**. 3. Open **New private key**. ### Generate the SSH key 1. Select **Generate ED25519**. Coolify generates and saves the key. 2. Select its **Edit** icon and enter a name such as `cooluser-key`. 3. Copy the complete **Public key**. 4. Select **Save changes**. Do not add a passphrase to the private key. Coolify must use it without an interactive prompt. ### Add the key to the new user Back in the root session on the server, run: ```sh install -d -m 700 -o cooluser -g cooluser /home/cooluser/.ssh nano /home/cooluser/.ssh/authorized_keys ``` Paste the public key on a new line and save the file. Then run: ```sh chown cooluser:cooluser /home/cooluser/.ssh/authorized_keys chmod 600 /home/cooluser/.ssh/authorized_keys ``` ### Allow passwordless sudo Make sure the `sudo` command is installed, then run these commands as `root`: ```sh echo 'cooluser ALL=(ALL) NOPASSWD: ALL' > /etc/sudoers.d/cooluser chmod 440 /etc/sudoers.d/cooluser ``` Check that the new user can use `sudo` without a password: ```sh su - cooluser -c 'sudo -n whoami' ``` The command should print `root` without asking for a password. ### Prepare the Coolify data directory Coolify stores application, database, service, proxy, and certificate files under `/data/coolify` on the server. Create the directory and give the non-root user ownership: ```sh mkdir -p /data/coolify chown -R cooluser:cooluser /data/coolify chmod -R o-rwx /data/coolify ``` The `cooluser` user can now manage files under `/data/coolify`. Coolify applies the same ownership pattern when it creates additional directories for a non-root server user. ### Continue to Add Server Follow [Connect the server](/core/infrastructure/servers/add-server#connect-the-server) to add and validate the server. When you complete the server form: - Enter `cooluser` in **User**. - Select the private key whose public key you added to `/home/cooluser/.ssh/authorized_keys`. - Skip the key-creation steps in that guide because the key is already configured. After validation, the server's **General** page should report **Server is reachable and validated**. If validation fails: - Run `su - cooluser -c 'sudo -n true'` again. A password prompt means the sudo rule is incorrect. - Run `passwd -S cooluser` and confirm the status is `P`. An `L` (locked) account rejects key-based logins. - Confirm the public key is in `/home/cooluser/.ssh/authorized_keys`. - Confirm **User** is `cooluser` in Coolify. - Check the [OpenSSH](/core/infrastructure/servers/openssh) settings and [firewall](/core/infrastructure/servers/firewall) rule for the SSH port. Coolify supports proxy operations, database starts/backups, deployments, log drains, and volume clones when the SSH user cannot directly write to `/data/coolify`. Keep the documented sudo access available rather than making resource data broadly writable.