How to add a user through SSH on Oracle Cloud

To add a new user to an Oracle Cloud compute instance, you connect via SSH as the default user (usually opc on Oracle Linux or ubuntu on Ubuntu images), then run the useradd command with a home directory flag, set a password, and optionally add the user to the sudo group. The entire process takes about five minutes and requires only terminal access — no Oracle Cloud console interaction needed after the instance is running.

This guide covers the SSH commands themselves, not the setup of your instance or key pair. If you have not yet connected to your Oracle Cloud instance over SSH, you will need your instance's public IP address and your private SSH key file before starting here.

Key Takeaways

  • Connect to your instance as the default user (opc or ubuntu) using your SSH key, then create the new user with sudo useradd -m -s /bin/bash username.
  • Set a password for the new user with sudo passwd username, then enter and confirm the password when prompted.
  • Add the user to the sudo group with sudo usermod -aG sudo username if they need administrative permissions.
  • Test the new account by opening a second terminal window and connecting as the new user to confirm SSH access works.

Connect to your instance as the default user

Open a terminal on your local machine and connect using your private key file. Replace your-instance-ip with your instance's public IP address and path/to/key.key with the path to your private SSH key:

ssh -i path/to/key.key opc@your-instance-ip

If your instance runs Ubuntu instead of Oracle Linux, use ubuntu instead of opc. You should see a command prompt that shows you are logged in. If the connection fails, check that your security list rules allow inbound traffic on port 22 and that your key file has the correct permissions (run chmod 600 path/to/key.key on your local machine if needed).

Create the new user account

Once connected, create the new user with a home directory and bash shell. Replace newusername with the actual username you want to create:

sudo useradd -m -s /bin/bash newusername

The -m flag creates a home directory at /home/newusername. The -s /bin/bash flag sets bash as the default shell. Without these flags, the user will have no home directory and may not be able to log in properly. The command produces no output if successful — no news is good news in this case.

Set a password for the new user

Now set a password for the account:

sudo passwd newusername

The system will prompt you to enter a new password, then ask you to retype it for confirmation. Use a strong password with uppercase, lowercase, numbers, and special characters. The password does not display as you type — this is normal. If the passwords do not match, the system will ask you to try again.

Grant sudo access (optional)

If the new user needs to run commands with administrative privileges, add them to the sudo group:

sudo usermod -aG sudo newusername

The -aG flags add the user to the sudo group without removing them from other groups. Without this step, the user can still log in and work, but cannot run sudo commands. You can skip this step if the user only needs regular (non-administrative) access.

Test the new account

Open a second terminal window on your local machine and test the new account by connecting as that user. You will need to use password authentication since the new user does not have an SSH key yet:

ssh newusername@your-instance-ip

The system will prompt you for the password you just set. Enter it and press Enter. If you see a command prompt with the new username, the account is working. Type exit to close the connection and return to your local terminal.

If the connection fails, go back to your original SSH session (still open in the first terminal) and verify the user was created by running id newusername. This command shows the user's ID and groups. If the user does not exist, the command will return an error.

Set up SSH key authentication for the new user (optional but recommended)

Password authentication works, but SSH keys are more secure. To let the new user log in with a key instead, they should generate a key pair on their local machine, then you add their public key to the instance. Have the new user run this on their local machine:

ssh-keygen -t rsa -b 4096

They will be prompted to choose a file location and passphrase. Once done, they should send you their public key file (usually ~/.ssh/id_rsa.pub). Back on the instance, still logged in as the default user, create the .ssh directory for the new user and add their public key:

sudo mkdir -p /home/newusername/.ssh

sudo nano /home/newusername/.ssh/authorized_keys

Paste the new user's public key into the file, save it (Ctrl+O, Enter, Ctrl+X in nano), then set the correct permissions:

sudo chmod 700 /home/newusername/.ssh

sudo chmod 600 /home/newusername/.ssh/authorized_keys

sudo chown -R newusername:newusername /home/newusername/.ssh

The new user can now log in with their SSH key without entering a password.

Frequently Asked Questions

What if I get a "permission denied" error when trying to create a user?

You must use sudo before the useradd command. The default user (opc or ubuntu) has sudo permissions by default, so sudo useradd -m -s /bin/bash newusername should work. If it still fails, verify you are logged in as the default user by running whoami.

Can I add a user without setting a password?

Yes, if you plan to use only SSH key authentication. Create the user and set up their public key in authorized_keys without running the passwd command. However, keeping a password as a backup is generally safer.

How do I remove a user I no longer need?

Run sudo userdel -r username to delete the user and their home directory. The -r flag removes the home directory and mail spool. Without it, the home directory remains on disk.

What if the new user cannot run sudo commands even after I added them to the sudo group?

The user may need to log out and log back in for the group change to take effect. Have them disconnect and reconnect via SSH, then try a sudo command again (for example, sudo whoami).

Can I add a user with a specific user ID number?

Yes, use the -u flag: sudo useradd -m -s /bin/bash -u 1500 newusername. This is useful if you need the user ID to match across multiple systems, but usually not necessary for Oracle Cloud instances.