Skip to content
Shellbay

Server Operations · about 1 min · 5 steps

Create a sudo user

Adds an account that signs in with your SSH key and can use sudo, so you don't need root.

Runs on

  • Debian / Ubuntu: supported
  • RHEL / Fedora: supported
  • Alpine: supported

What it changes on your server

  • Creates the account (unless it exists) with a home directory.
  • Adds your public key to its ~/.ssh/authorized_keys.
  • Adds it to the sudo (Debian, Ubuntu) or wheel (RHEL, Fedora, Alpine) group.
  • Optionally lets it use sudo without a password (in /etc/sudoers.d).

What Shellbay asks you

  1. What should the account be called?

    Use lowercase letters, digits, - and _. You'll sign in as this user instead of root, and use sudo for administration.

    Username
    A new Linux account name

    Example: deploy

    Shellbay checks no account with that name exists yet.

  2. Which key will sign in?

    Paste one public key line. In Shellbay, open Keys, choose a key and copy its public key. Private keys never leave your device.

    Public key
    One SSH public key line

    Example: ssh-ed25519 AAAAC3Nz… you@ipad

  3. Use sudo without a password?

    The account has no password, since it signs in with a key, so sudo can't ask for one. Turn this on to use sudo straight away. If you turn it off, set a password as root with passwd <username> before using sudo.

    Allow sudo without a password
    On or off. Default: on

Steps

  1. Make sure sudo is installed
  2. Create the account
  3. Add your public key
  4. Set up sudo
  5. Check the account

Shellbay checks the server before the first step, and stops at the first step that fails.

When it's done

  • ‹username› can sign in with your key. In Shellbay, add a host for ‹username› with that key and connect once to check.
  • Once that works, consider the SSH hardening workflow to turn off root and password sign-in.