First boot now authenticates its own `FLUSH PRIVILEGES` (it used to run unauthenticated and die with ERROR 1045), verifies `root` against the running server and only then writes /root/.mysql-initial-password and the completion marker. The password survives reboots.
If you deployed this VM before 2026-09-16, it came from the older image and is not changed by the new publication — redeploy from the current Marketplace version, or apply the one-time repair below:
sudo mkdir -p /etc/app && sudo touch /etc/app/.firstboot-completeImage change: see the pull request.
Source: the Marketplace live version set for this offer, read from Partner Center on 2026-09-16. New deployments take the newest version by default.
| Application ports | 3306 (MySQL) — server binds 127.0.0.1 until you change bind-address |
|---|---|
| Admin credential file | sudo cat /root/.mysql-initial-password |
| Sign in as | root (root@localhost, caching_sha2_password) |
| Service(s) | mysql |
| Configuration | /etc/mysql/mysql.conf.d/mysqld.cnf (bind-address) |
| Logs | /var/log/mysql/error.log; journalctl -u mysql -f |
| Version | MySQL 8.0 (Ubuntu 24.04 package) |
| Platform | Ubuntu 24.04 LTS |
This image generates its admin credential on the VM at first boot — nothing is pre-set. SSH into the VM with the username + key you chose at deploy, then print the generated credential:
ssh <your-username>@<VM-IP>
sudo cat /root/.mysql-initial-passwordSign in as root (root@localhost, caching_sha2_password).
This is the MySQL root password set at first boot (root@localhost uses caching_sha2_password, so plain `sudo mysql` is refused). Connect with `mysql -u root -p`, change it with ALTER USER, and delete the file once stored securely.
| Symptom | Check | Fix |
|---|---|---|
| `sudo mysql` says access denied for root@localhost | sudo cat /root/.mysql-initial-password | Root has a password on this image (not auth_socket): use `mysql -u root -p`. |
| Remote client cannot connect | bind-address in /etc/mysql/mysql.conf.d/mysqld.cnf; NSG rule for 3306 | Both must be opened deliberately; the in-image firewall already allows 3306. |
Email support@dcassociatesgroup.com (response within 1 business day) or send a
message via the contact form. Include the offer name, VM size, region, and any log output — sudo journalctl -u <service> -n 100 usually tells the story.