Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / PostgreSQL 16 on Ubuntu 24.04 LTS

PostgreSQL 16 on Ubuntu 24.04 LTS — Support & Quick Start

Production-ready PostgreSQL 16 on Ubuntu 24.04 LTS. Hardened, Trusted Launch enabled, per-VM generated postgres password, accepting connections within minutes of first boot.

At a glance

Application ports5432 (PostgreSQL, TLS available) — listen_addresses = '*' and a `host all all 0.0.0.0/0 md5` rule are pre-set; only the NSG keeps it closed
Admin credential filesudo cat /root/.postgresql-initial-password
Sign in aspostgres (superuser; password auth over the network, peer auth locally)
Service(s)postgresql
Configuration/etc/postgresql/16/main/postgresql.conf (ssl = on); /etc/postgresql/16/main/pg_hba.conf; TLS certificate /etc/ssl/certs/ssl-cert-snakeoil.pem and key /etc/ssl/private/ssl-cert-snakeoil.key, a self-signed pair generated on your VM at first boot
Logs/var/log/postgresql/postgresql-16-main.log
VersionPostgreSQL 16 (PGDG packages)
PlatformUbuntu 24.04 LTS

Quick start

  1. SSH into the VM with the username and key you chose at deploy.
  2. PostgreSQL 16 runs as the `postgresql` systemd service. This image sets listen_addresses = '*' and a `host all all 0.0.0.0/0 md5` rule in /etc/postgresql/16/main/pg_hba.conf, and the in-image ufw allows 5432 — only the NSG keeps 5432 closed until you open it.
  3. Connect locally with `sudo -u postgres psql`, create your application role and database, restrict pg_hba.conf to your subnets, then open 5432 in the NSG to your app tier only.

First login / credentials

This image generates its admin credential on the VM at first boot — nothing is pre-set. SSH into the VM with the username + key you chose at deploy, then print the generated credential:

ssh <your-username>@<VM-IP>
sudo cat /root/.postgresql-initial-password

Sign in as postgres (superuser; password auth over the network, peer auth locally).

  1. Print the generated postgres password from the file (local `sudo -u postgres psql` still works via peer auth).
  2. Network clients: psql "host=<VM-IP> user=postgres sslmode=require" with that password. TLS is on with a self-signed certificate generated on this VM at first boot, so `sslmode=require` encrypts the session; for `verify-full`, replace the pair with a CA-issued certificate. pg_hba.conf uses `host` rules, so clients that do not ask for TLS are still accepted until you change them to `hostssl`.
  3. Create your application role and database, tighten pg_hba.conf to your subnets, change the password (ALTER USER), and delete the file.

This is the password of the `postgres` superuser, set at first boot. Local `sudo -u postgres psql` still works (peer auth); network clients use this password over md5 until you tighten pg_hba.conf. Change it with ALTER USER and delete the file once stored securely.

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or send a message via the contact form. Include the offer name, VM size, region, and any log output — sudo journalctl -u <service> -n 100 usually tells the story.