Installation / First boot and network

First boot and network

What happens on the first boot, how to sign in, and how to set the management address.

On this page
  1. What happens on the first boot
  2. The first-time setup
    1. Create the administrator password
    2. The setup steps
  3. Sign-in
  4. The management address
    1. DHCP
    2. Static address
    3. Network cards
  5. What is open on the network
  6. Check the install

What happens on the first boot#

On its first boot the appliance gives itself a fresh identity and starts the platform. It creates its own TLS certificate and key, a new machine ID and new SSH host keys, so no two appliances share an identity. It does not set a password for you: you create the administrator password yourself, in your browser, the first time you open the appliance. Nothing of this is baked into the image.

Wait until the web interface answers. When the platform is up, the virtual machine's console shows the ONEP banner above the login prompt. It shows:

  • a Status line: Starting — no start-up report yet, Platform ready with the start-up time, or Platform not ready with the step that did not complete. If the installation did not finish, the line says Installation incomplete;
  • a Virtual machines line, only when nested virtualization is not available, saying that virtual machines are not available until it is enabled on your hypervisor;
  • the address to open in a browser, https://<address>/.

The address line refreshes every five minutes, so it follows a DHCP change. The console login prompt below the banner is for the operating system account created at install, not for ONEP; you do not need it.

On every start the appliance also checks the size of its virtual disk. If you enlarged the disk in your hypervisor, it grows its main partition and file system to use the space. It does this only when the system disk is a plain partition, and it never stops the start-up.

When you shut the virtual machine down from the hypervisor, the appliance powers off running devices and stops its services within a short time limit before the system halts. Shut down from the hypervisor rather than cutting power.

The first-time setup#

The first time you open the address, ONEP shows its setup pages in place of the sign-in page. Nothing else in the product works until the agreement is accepted.

Create the administrator password#

  1. Open the address in a browserA current Chromium-based browser is the tested default.
  2. Accept the certificate warningThe appliance uses the certificate it created on first boot, which your browser does not know yet. This is expected on every install.
  3. Choose a passwordThe page is headed Create the administrator password and has two fields, Password and Confirm password. Use 12 to 72 characters. A line under each field tells you what is missing: At least 12 characters., Meets the requirements. or The passwords do not match.
  4. Choose Create and sign inThe account is always named admin, and you are signed in at once. ONEP does not generate a password: nothing is shown on the console and nothing is written to a file.

Until the password is created, whoever opens the address first can create it, so do this step yourself right after the appliance starts. The page works once. Afterwards it says The administrator password has already been set. Sign in instead.

The setup steps#

After you sign in, First-time setup lists six steps down the left side: Agreement, Administrator, License, Network, ONEP Assistant and Ready. The header shows Step n of 6. The Administrator step is already done, because you created the password. The page keeps your place on the appliance, so a reload, another browser or a restart resumes at the first step you have not finished. Signing in before the setup is finished sends you back to it.

StepWhat you doSkip for now
AgreementRead the agreement. The checkbox I have read and accept this agreement turns on when you scroll to the end. Choose Continue. Until you accept, the platform answers Finish the first-time setup to use ONEP.No
LicenseChoose Choose license file and select onep.lic. The This appliance card then lists the edition, seats, expiry and who the license was issued to. See Licensing.Yes. The appliance runs as Community until you install a license.
NetworkChoose Automatic (DHCP), which is recommended, or Static address and fill in Address, Subnet (prefix), Gateway, Primary DNS and Secondary DNS. The Detected address card shows the address you are using now. If you change the address, a confirmation tells you that this session ends and you reconnect at the new address. If nothing changes, the wizard does not touch the network.Yes
ONEP AssistantChoose Model on this appliance, which is recommended, or External AI service (your own account), which asks for Service address, Model name and Key. The key is stored on the appliance and never shown again. Prompts leave the appliance when an external service is used. See AI Generator.Yes
ReadyShows the address to bookmark and a short list of what to do first: register a device image, create an environment, power it on and open a console, and confirm a backup ran. It names any step you skipped, and warns if nested virtualization is not available. Choose Open ONEP.Not applicable

Back returns to the previous step. A step you skip is recorded, and each one can be completed later in Settings.

Sign-in#

After the first-time setup, you sign in on the sign-in page. It has Username or email and Password fields and a Sign in button, and under the form one line with the product, edition, version and build.

  1. Sign in as adminwith the password you created.
  2. Enter the two-factor code, if you turned it onThe page asks for Two-factor code, the six digits from your authenticator app. Choose Verify & sign in, or Back to start again.
  3. Set a new password, if askedIf a password change is required, the page shows Set a new password: at least 12 characters, different from the current one. This step cannot be skipped.

Turn on two-factor authentication under Settings › Account with Set up two-factor. On Community and Lite the administrator is the only account, so the page points you to hello@onep.io to reset two-factor.

After the first sign-in you set everything else in Settings: the license in Licensing, the management address in Network, and the AI source in AI.

The management address#

The appliance has one management interface. It is the address you and your browser use, and the only address the appliance needs on your network. Environments do not use it: each one runs on its own isolated virtual network.

DHCP#

On first boot the appliance takes an address by DHCP on its first network interface. Settings › Network shows it under Management interface, with the address, gateway and DNS servers it received. That is fine to keep. If you keep DHCP, reserve the address in your DHCP server so it does not move; if it does move, the console banner shows the new one within five minutes.

Static address#

  1. Open Settings › Networkas an administrator. Management interface shows the live address, gateway and DNS servers.
  2. Set Address mode to Static addressand enter IP address, Subnet (prefix), Gateway and Primary DNS. Secondary DNS is optional. The prefix is a number from 1 to 32.
  3. Choose Apply static IPand confirm. Your browser session drops, because the address it was using changes. Open the new address to sign in again.

To go back to DHCP, set Address mode to Automatic (DHCP) and choose Use DHCP. The message on the page says to check your DHCP server for the new address.

ONEP puts the previous settings back if the appliance cannot reach its gateway about 25 seconds after the change. If the live network state cannot be read, the page says The live network state could not be read just now; these are the last saved values.

Network cards#

The management interface is the only address ONEP asks you to set. On an appliance that is not on Community or Lite, Settings › Advanced has an Environment uplink card: the network card environments use to reach your network. On Community and Lite the cloud node on the canvas is the uplink, and the card is not shown.

Remote access is separate

The Network tab only sets the address on your LAN. Publishing the appliance outside your network is a deliberate step in Settings › Remote access. See Remote access.

What is open on the network#

  • The host firewall opens 80/tcp and 443/tcp, and a WireGuard UDP port when remote access is enabled. Everything else inbound is closed.
  • Device console ports are closed; consoles go through the web interface.
  • The firewall does not open SSH. Use the web interface, and the hypervisor's own console for the virtual machine.

The full list is in Network and ports.

Check the install#

From a machine that can reach the appliance, after you have created the administrator password:

curl -sk https://<address>/api/system/edition

The reply names the edition and the limits it sets. On Lite it includes "edition":"lite" and "runtime_enabled":true. On Community it includes "edition":"community". If the edition is not the one you bought, the license did not install; see Licensing.

Something wrong or missing on this page? Write to hello@onep.io.