opensearch.service is given 10 minutes to start instead of 75 seconds, the generated admin password is hashed with the bundled JDK and written into /etc/opensearch/opensearch-security/internal_users.yml (the step that used to die silently when `java` was not on PATH), and first boot verifies the password against the running node.
If you deployed this VM before 2026-09-16, it came from the older image and is not changed by the new publication — redeploy from the current Marketplace version, or apply the one-time repair below:
Image change: see the pull request.
Source: the Marketplace live version set for this offer, read from Partner Center on 2026-09-16. New deployments take the newest version by default.
| Application ports | 5601 (Dashboards, HTTP), 9200 (REST API, HTTPS with the bundled self-signed demo certificates) |
|---|---|
| Open in browser | http://<VM-IP>:5601/ |
| Admin credential file | sudo cat /var/lib/opensearch/admin-password |
| Sign in as | admin |
| Service(s) | opensearch, opensearch-dashboards |
| Configuration | /etc/opensearch/opensearch.yml; /etc/opensearch/opensearch-security/internal_users.yml; /etc/opensearch-dashboards/opensearch_dashboards.yml |
| Logs | /var/log/opensearch/; journalctl -u opensearch-dashboards -f |
| Version | OpenSearch 3.0.0 + OpenSearch Dashboards (3.x apt repository) |
| Platform | Ubuntu 24.04 LTS |
This image generates its admin credential on the VM at first boot — nothing is pre-set. SSH into the VM with the username + key you chose at deploy, then print the generated credential:
ssh <your-username>@<VM-IP>
sudo cat /var/lib/opensearch/admin-passwordSign in as admin.
Sign in as admin. The REST API on 9200 is HTTPS with self-signed demo certificates (use -k / your CA); replace them and rotate the password before exposing the node.
Email support@dcassociatesgroup.com (response within 1 business day) or send a
message via the contact form. Include the offer name, VM size, region, and any log output — sudo journalctl -u <service> -n 100 usually tells the story.