Skip to main content
Use • 2 mins read

Virtual Machines

Virtual Machines

A Hippius virtual machine is a Linux server that runs inside an AMD SEV-SNP enclave, so the host can't read its memory or its disk. This guide takes you from an SSH key to a running VM you are logged in to. It takes about ten minutes, most of it waiting for the VM to boot.

Open VMs from the sidebar: Confidential Computing →

Virtual Machines
. The page has three tabs: Instances (your VMs), Templates (the sizes you can launch) and SSH Keys (the public keys saved to your account).

Before you start
  • Your balance must cover 24 hours of your compute, including the new VM. The create form tells you if it doesn't. See the 24-hour balance requirement.
  • You need an SSH key pair. If you don't have one, generate it first (next section).

Generate an SSH key pair with ssh-keygen​

Your VM has no password login: you sign in with an SSH key. The key pair has two halves. The private key stays on your computer, and you give Hippius the public key.

On macOS, Linux or Windows (PowerShell), run:

ssh-keygen -t ed25519

Press Enter to accept the default location (~/.ssh/id_ed25519, or C:\Users\YOUR_NAME\.ssh\id_ed25519 on Windows). You can set a passphrase to protect the private key.

Then print the public key and copy the whole line:

cat ~/.ssh/id_ed25519.pub

On Windows PowerShell, use type $env:USERPROFILE\.ssh\id_ed25519.pub instead. The line starts with ssh-ed25519.

Use an ed25519 or RSA key

Saved keys must be OpenSSH public keys that start with ssh-ed25519 or ssh-rsa. Never paste your private key anywhere: it is the only way into your VM, and nobody, Hippius included, can recover or reissue it.

Create a virtual machine​

On the Instances tab, click + New VM. The create page is one form in numbered steps, with a Summary panel that keeps the price, your quota and your balance up to date as you choose.

1. Choose an image​

Pick what the VM starts from. Use the switch at the top of the step to choose between:

  • Distributions: a plain Linux distribution, such as Ubuntu, Debian or Fedora. The list comes from the images available right now. Size default boots the image the chosen size uses by default.
  • Applications: software that is installed and configured for you on first boot, such as WordPress. An application picks its own image, and may need a minimum size. When you select one, its settings appear below it.

Some applications are managed services: Hippius administers the machine, so it has no shell and takes no SSH key. The form tells you when that is the case.

2. Choose a region​

Leave Automatic (any region) to let the network place the VM on any verified server, or pick a country to pin it there. Only countries with a verified server that has room right now are listed.

Under the list, the form tells you whether your choice can launch now. If a region is tight, launching may take longer. If no server in the region can take the size you chose, pick another region or a smaller size.

3. Choose a size​

Each size card shows its vCPUs, memory (RAM), disk and its price per hour and per month. The Templates tab lists the same sizes. Select a size to see its price broken down into vCPU, memory and disk.

A size can be greyed out. Coming soon means it isn't available yet. Too small for an application means the application needs a bigger size. The region message means no server in that region can take it right now.

The disk can't grow later

You can resize the vCPUs and memory of a VM later, but its disk keeps the size it was launched with. Pick a size whose disk is big enough.

4. Authentication​

Select every SSH key that should be able to log in. Each selected key can log in as the VM's default user. Saved keys show their name and fingerprint.

To add a key here, click Add new key, give it a name (for example laptop), paste the public key and click Save and select. It is saved to your account for next time.

You can select up to 20 keys per VM. You must select at least one, unless you picked a managed service.

5. Add-ons​

These are optional. Each one is added to the price in the summary.

  • Automatic backups: encrypted copies of the disk, kept 7 days, taken at the interval you choose. They turn on once the VM is running. See VM backups.
  • Public IPv4: a dedicated public address for this VM. Inbound traffic is blocked unless a firewall rule allows it. It is off by default.
  • Open SSH (port 22) to the internet: shown once you tick Public IPv4, and on by default. It creates a firewall rule named SSH (opened at launch) that lets anyone reach port 22. Ping (ICMP) is always allowed. You can restrict or delete that rule later; see Restrict SSH to your own address.

Without a public IPv4, the VM can't be reached from the internet. You can still open a shell from the browser, and you can attach an address later. See Public IPv4 and firewall.

6. Finalize details​

Give the VM a Name of up to 64 characters, such as web-1.

Review and launch​

Check the Summary panel. It lists the image, region, size, SSH keys, add-ons and the total per hour and per month. Below that it shows your quota after the launch and your balance.

If your balance doesn't cover 24 hours of your compute with this VM, the form says so and holds the button. Top up from the link it shows, then come back. See the 24-hour balance requirement.

Click Create VM. The console says Virtual machine launching and opens the VM's page.

Follow the boot​

The VM's status starts at Pending, then moves to Provisioning and Running. The Boot Phase goes from Booting to Disk unsealed (the VM passed attestation and its encrypted disk was unlocked) and then to Running. A first boot usually takes a few minutes.

If the launch fails, the VM's page says why and what to try, for example another region or a smaller size. Nothing is billed for a VM that never ran. See Troubleshooting.

Connect to your VM via SSH​

There are three ways in:

  • Over SSH, through the VM's public IPv4, if you added one and port 22 is open.
  • From the browser, with the Console tab on the VM's page. This works without a public IP.
  • From your private network, for example from another of your VMs.

Find the username​

Sign in as the image's default user, not root. It depends on the distribution:

ImageUsername
Ubuntuubuntu
Debiandebian
Fedorafedora
CentOS Stream, RHELcloud-user
Rocky Linuxrocky
AlmaLinuxalmalinux
openSUSEopensuse
Arch Linuxarch

The browser terminal fills the right username in for you. The default user can use sudo.

Connect over the public IPv4​

Copy the address from IP Address on the VM's page (Copy Public IP), then run:

Replace ubuntu with your image's username and 203.0.113.10 with your VM's address. If your private key is not in the default location, add -i:

ssh -i ~/.ssh/id_ed25519 [email protected]

Connect from the browser​

Open the VM's page and click the Console tab (or Access Console in the VM's menu on the Instances tab).

  1. Paste the private key that matches one of the VM's public keys, or click Choose key file.
  2. Under Advanced, check the Username, and enter the Key passphrase if your key has one.
  3. Click Connect.

The SSH handshake runs in your browser tab. Hippius relays encrypted traffic it can't read, and your key is kept in memory only and discarded when you leave the page. Ed25519, RSA and ECDSA private keys work.

The Console tab is only available once the VM is running and on your private network. It isn't available while the VM is resized, and managed services have no shell.

Connect from your private network​

Every VM joins your account's private network when it first boots. The VM's page shows its address on that network (Copy Overlay IP). Your other VMs and services on the same network can reach it there, for example with ssh ubuntu@<overlay IP> from another of your VMs.

SSH troubleshooting​

Permission denied (publickey). Check the username first: logging in to a Fedora VM as ubuntu fails with this same error. Then check that you are using the private key that matches one of the public keys you selected at launch. On macOS and Linux, the private key file must not be readable by others: chmod 600 ~/.ssh/id_ed25519.

Connection timed out. Check that the VM is Running, that it has a public IPv4, and that a firewall rule allows port 22 from your address. See Public IPv4 and firewall.

No public IP. Use the Console tab, or attach a public IPv4 from the VM's page.

Manage saved SSH keys​

The SSH Keys tab lists the public keys saved to your account. Click + New SSH Key to add one: give it a name, paste the public key and save it. You can save up to 10 keys.

A saved key can't be edited, only deleted. Deleting a key doesn't remove it from VMs that already have it. Changing the keys on a VM is done inside the VM, in the default user's ~/.ssh/authorized_keys file.

Start, stop and reboot​

Use the VM Controls card on the VM's page, or the VM's menu on the Instances tab:

  • Stop powers the VM off. Its disk and its private network address are kept.
  • Start powers a stopped VM back on.
  • Reboot restarts it.

These actions are only available on a VM that has finished provisioning. Managed services can't be powered from here.

A stopped VM is still billed

A stopped VM keeps its server capacity reserved, so it is billed at its full price. The list marks stopped VMs Billed while stopped. Delete the VM to stop paying.

Delete a VM​

Open the VM's menu and choose Delete, then confirm with Delete Instance.

Deleting is permanent:

  • The encrypted disk is crypto-erased. The data can't be recovered.
  • The VM's public IPv4, if it has one, goes back to the pool. You may not get the same address again.
  • Billing stops when you ask to delete, not when the teardown finishes.

You can't delete a VM while it is being resized. Wait for the resize to finish.

Where to next​