Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Grafana + Prometheus on Ubuntu 24.04 LTS

Grafana + Prometheus on Ubuntu 24.04 LTS — Support & Quick Start

Grafana 13 + Prometheus 3 observability stack on Ubuntu 24.04 LTS, Prometheus pre-wired as the default data source, with a unique per-VM admin password.

At a glance

Application ports3000 (Grafana), 9090 (Prometheus UI/API, no built-in auth)
Open in browserhttp://<VM-IP>:3000/
Admin credential filesudo cat /var/lib/grafana-firstboot-admin-pw
Sign in asadmin
Service(s)grafana-server, prometheus
Configuration/etc/grafana/grafana.ini; /etc/prometheus/prometheus.yml (Prometheus scrapes only itself until you add targets; TSDB in /var/lib/prometheus/); data source provisioning /etc/grafana/provisioning/datasources/prometheus.yml (default data source `Prometheus`, uid `prometheus`)
Logsjournalctl -u grafana-server -f; /var/log/grafana/grafana.log; journalctl -u prometheus -f
VersionGrafana 13 (official Grafana apt repository, current at build: 13.2.3 in image 2026.1001.1524) + Prometheus 3.15.0
PlatformUbuntu 24.04 LTS

Quick start

  1. Open http://<VM-IP>:3000/ in your browser (allow inbound 3000 — and 9090 if you want the Prometheus UI — in the NSG; the in-image ufw already allows both).
  2. Sign in as `admin` with the generated password (see command below), then change it immediately.
  3. Prometheus (http://<VM-IP>:9090/, no built-in auth) is provisioned as Grafana's default data source and scrapes itself; add your own scrape targets in /etc/prometheus/prometheus.yml and `sudo systemctl restart prometheus`.

First login / credentials

This image generates its admin credential on the VM at first boot — nothing is pre-set. SSH into the VM with the username + key you chose at deploy, then print the generated credential:

ssh <your-username>@<VM-IP>
sudo cat /var/lib/grafana-firstboot-admin-pw

Sign in as admin.

  1. Print the generated admin password from the file (first boot resets Grafana's admin password to it and, since image version 2026.915.2216, proves the sign-in against the running server before writing the file).
  2. Open http://<VM-IP>:3000/ and sign in as admin. If the password is rejected you are on an image older than 2026.915.2216 — use the reset command in Troubleshooting below.
  3. Change the password (Profile → Change password) and delete the file. Prometheus on :9090 has no authentication — keep it closed in the NSG or front it with auth. Prometheus 3 serves its new web UI on that port (`/` opens `/query`); the old `/consoles/` example pages are gone.

Sign in as admin with the generated password. Image version 2026.915.2216 (published 2026-09-16) is the first build whose first-boot reset reaches Grafana's live database; deploying the offer's default ‘latest’ gives you a build with that fix. On VMs from an earlier image — including a deployment that explicitly pins an older version — the password is rejected, and the manual reset in Troubleshooting is the cure; it works on every image.

Troubleshooting

SymptomCheckFix
Admin password rejected at :3000 ("Invalid username or password")sudo cat /var/lib/grafana-firstboot-admin-pw exists, you are signing in as admin, and the image version this VM was deployed fromFixed in image version 2026.915.2216 (published 2026-09-16, image-factory PR #204) — first boot now writes the running server's own database and verifies the login before recording the password. Older versions are still published on this offer and still carry the defect: the first-boot reset wrote /usr/share/grafana/data/grafana.db instead of the database the server reads, so the generated password is not the live one. Deploying ‘latest’ gets you the fixed build; if you deployed before 2026-09-16 or pinned an older version, reset the password with the command below and sign in with the value you chose.
Password file missingsudo systemctl status firstboot; sudo journalctl -u firstbootFirst boot writes the file only after the reset step; if it is absent, run the reset command below and sign in with the password you chose.
Grafana login page not loadingsudo systemctl status grafana-server; NSG allows 3000sudo systemctl restart grafana-server; open TCP 3000 in the NSG to your IP.
A PromQL query you wrote for Prometheus 2 returns different resultscurl -s http://127.0.0.1:9090/api/v1/status/buildinfo ("version": "3.15.0" on images from 2026-10-01)Prometheus 3 changed some query semantics: `.` in a regex now matches newlines, range selectors no longer include a sample exactly on the left boundary, `le`/`quantile` label values are stored as floats (`le="1.0"`, not `le="1"`), and `holt_winters` is now `double_exponential_smoothing`. See the Prometheus 3 migration guide (prometheus.io/docs/prometheus/latest/migration/).
sudo GF_PATHS_DATA=/var/lib/grafana grafana-cli --homepath /usr/share/grafana --config /etc/grafana/grafana.ini --configOverrides "cfg:default.paths.data=/var/lib/grafana" admin reset-admin-password '<new>'

Replace <new> with a strong password of your own. The Debian package leaves [paths] data commented out in /etc/grafana/grafana.ini and hands DATA_DIR=/var/lib/grafana to grafana-server only through /etc/default/grafana-server, so grafana-cli with --homepath alone OR with --config alone silently writes a different database (/usr/share/grafana/data/grafana.db) and still reports success. GF_PATHS_DATA plus the cfg:default.paths.data override makes the CLI write /var/lib/grafana/grafana.db — the database the running server uses — and no restart is needed (verified on a live VM 2026-09-15, image-factory PR #204). The permanent fix ships in image version 2026.915.2216, live on the Marketplace since 2026-09-16: first boot resets with these overrides and verifies the login against the running server before writing the password file. The older versions remain selectable on this offer and still have the defect, so if you pin a version rather than take the default ‘latest’, this manual reset is still the supported path.

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or send a message via the contact form. Include the offer name, VM size, region, and any log output — sudo journalctl -u <service> -n 100 usually tells the story.