---
title: Non-root User
description: Create a non-root SSH user and give it the access Coolify needs to manage a server.
---
# Use a non-root server user
Coolify can connect to a server using an account other than `root`. This feature is experimental and still requires the account to run commands with passwordless `sudo`.
The user created in this guide can run any command as `root` without entering a password. Use a dedicated account and SSH key only for Coolify.
This guide uses `cooluser` as the username. Replace `cooluser` with the username you want to use.
---
## Configure the non-root user
### Sign in as root
Connect to the server as `root` using SSH or the server console.
Keep this session open until Coolify successfully validates the new account.
### Create the user
Run the command for the server's operating system.
```sh
useradd --create-home --user-group --shell /bin/bash --password 'NP' cooluser
```
Use this for CentOS, RHEL, Rocky Linux, AlmaLinux, Fedora, Amazon Linux, Oracle Linux, or TencentOS.
```sh
useradd --create-home --user-group --shell /bin/bash --password 'NP' cooluser
```
```sh
useradd --create-home --user-group --shell /bin/bash --password 'NP' cooluser
```
```sh
useradd --create-home --user-group --shell /bin/bash --password 'NP' cooluser
```
```sh
adduser -D -s /bin/ash cooluser
```
`--password 'NP'` leaves the account unlocked while keeping password login disabled (`NP` is not a valid hash). A brand-new account otherwise has a locked password (`!` in `/etc/shadow`), and OpenSSH refuses key-based logins to a locked account, so Coolify's server validation fails.
Alpine's busybox `adduser` has no equivalent flag, so its account stays locked. Alpine's OpenSSH is built without PAM and still accepts key-based logins, so no change is needed. If your Alpine build uses PAM, unlock the account with `apk add shadow && usermod -p 'NP' cooluser`.
Confirm the account exists and is not locked:
```sh
id cooluser
passwd -S cooluser
```
`id` prints the user's ID and group information. In `passwd -S`, the status field (second column) should be `P`, not `L`.
### Open the Coolify dashboard
1. Select **Keys & Tokens** in the sidebar.
2. Select **Private Keys**.
3. Open **New private key**.
### Generate the SSH key
1. Select **Generate ED25519**. Coolify generates and saves the key.
2. Select its **Edit** icon and enter a name such as `cooluser-key`.
3. Copy the complete **Public key**.
4. Select **Save changes**.
Do not add a passphrase to the private key. Coolify must use it without an interactive prompt.
### Add the key to the new user
Back in the root session on the server, run:
```sh
install -d -m 700 -o cooluser -g cooluser /home/cooluser/.ssh
nano /home/cooluser/.ssh/authorized_keys
```
Paste the public key on a new line and save the file. Then run:
```sh
chown cooluser:cooluser /home/cooluser/.ssh/authorized_keys
chmod 600 /home/cooluser/.ssh/authorized_keys
```
### Allow passwordless sudo
Make sure the `sudo` command is installed, then run these commands as `root`:
```sh
echo 'cooluser ALL=(ALL) NOPASSWD: ALL' > /etc/sudoers.d/cooluser
chmod 440 /etc/sudoers.d/cooluser
```
Check that the new user can use `sudo` without a password:
```sh
su - cooluser -c 'sudo -n whoami'
```
The command should print `root` without asking for a password.
### Prepare the Coolify data directory
Coolify stores application, database, service, proxy, and certificate files under `/data/coolify` on the server.
Create the directory and give the non-root user ownership:
```sh
mkdir -p /data/coolify
chown -R cooluser:cooluser /data/coolify
chmod -R o-rwx /data/coolify
```
The `cooluser` user can now manage files under `/data/coolify`. Coolify applies the same ownership pattern when it creates additional directories for a non-root server user.
### Continue to Add Server
Follow [Connect the server](/core/infrastructure/servers/add-server#connect-the-server) to add and validate the server.
When you complete the server form:
- Enter `cooluser` in **User**.
- Select the private key whose public key you added to `/home/cooluser/.ssh/authorized_keys`.
- Skip the key-creation steps in that guide because the key is already configured.
After validation, the server's **General** page should report **Server is reachable and validated**.
If validation fails:
- Run `su - cooluser -c 'sudo -n true'` again. A password prompt means the sudo rule is incorrect.
- Run `passwd -S cooluser` and confirm the status is `P`. An `L` (locked) account rejects key-based logins.
- Confirm the public key is in `/home/cooluser/.ssh/authorized_keys`.
- Confirm **User** is `cooluser` in Coolify.
- Check the [OpenSSH](/core/infrastructure/servers/openssh) settings and [firewall](/core/infrastructure/servers/firewall) rule for the SSH port.
Coolify supports proxy operations, database starts/backups, deployments, log drains, and volume clones when the SSH user cannot directly write to `/data/coolify`. Keep the documented sudo access available rather than making resource data broadly writable.