NEW Bare Metal Servers with 20G Dedicated Unmetered Bandwidth 20G Dedicated Unmetered Servers Read more STATUS

Boot Into Single-User Mode to Reset a Root Password or Fix a Broken Boot (Ubuntu, Debian, AlmaLinux, Rocky)

Sep 15, 2026 6 min read

Single-user mode (called rescue or emergency mode on modern systems) drops your Linux server into a root shell before a single service starts, and, if you want, before anything asks for the root password. You get there from the remote console by editing the boot entry for one boot. Nothing gets written to the boot configuration. When you've lost the root password, it's the fastest fix, and it's also how you repair an /etc/fstab that keeps the system from booting, switch off a service that hangs startup, or run a filesystem check.

When to use it, and when not. For single-user mode, the boot loader still has to load and the kernel still has to start. If you never reach a GRUB menu, or the kernel panics, switch to rescue mode. That boots a separate system over the network and doesn't touch your disks until you mount them. Both methods need the console. Neither needs SSH.

All of the steps below take place in the machine's remote console. Open it before anything else (bare metal: the server's Console button; cloud: the instance's Console button). Then start a reboot from the portal header and keep your eyes on the console as the machine powers on.

Step 1: Get to the boot menu

  • Cloud instances display the GRUB menu on the serial console for a few seconds. Hit any arrow key while it's up and the countdown stops.
  • Bare metal normally keeps the menu hidden. The moment the firmware screen goes away, hold Shift (BIOS boot) or tap Esc repeatedly (UEFI boot). The window is short, so if the system boots straight past it, reboot and try again.
  • On Ubuntu, a boot that failed to finish brings up the menu on its own next time. Stock Debian shows it on every boot.
The GRUB boot menu on a server console with the first entry highlighted and the hint to press e to edit the commands before booting
The GRUB menu. Select the normal entry, then press e.

Step 2: Edit the entry for this boot only

Highlight the normal entry and press e. Arrow down to the line beginning with linux (it's long, and it may wrap), move to the very end, and add one option. Press Ctrl+X (or F10) to boot with it. On the next boot, GRUB has already forgotten the change.

System Add to the linux line What you get
Ubuntu, Debian systemd.unit=rescue.target A root shell, once you give the root password (if root has one). Filesystems are mounted, the network is down.
Ubuntu, Debian (root has no password, or you lost it) init=/bin/bash A root shell, and nothing asks for a password. The root filesystem stays read-only until you remount it (Step 3).
AlmaLinux, Rocky, RHEL, CentOS Stream rd.break A shell in the early boot environment, without a password prompt. Your system sits under /sysroot.
Any systemd system with disk trouble systemd.unit=emergency.target The barest shell there is: root is mounted read-only and nothing else is mounted. Use it for fstab and fsck jobs.

Remove quiet and splash from that line too if you'd like to see boot messages. You'll want them when the whole point is finding out where the boot stops.

The GRUB edit screen on a server console showing the linux kernel line with rd.break appended at the end, and the hint to press Ctrl-x to boot
The edit screen. Put the option at the very end of the linux line.

Step 3: Make the filesystem writable

Unless you booted into rescue.target, the root filesystem is read-only right now. Remount it before you change anything:

# Ubuntu / Debian (rescue.target or init=/bin/bash)
mount -o remount,rw /

# AlmaLinux / Rocky (rd.break) — the system lives under /sysroot
mount -o remount,rw /sysroot
chroot /sysroot
A server console showing the systemd rescue mode prompt asking for the root password for maintenance, followed by a root shell
If root has a password, rescue mode asks for it. The other routes put you straight into a shell.

Step 4: Do the repair

Reset the root password:

passwd root

On AlmaLinux, Rocky and any other SELinux system, run this too before you leave, so the changed file gets its security label back. Without it, the login prompt rejects the new password:

touch /.autorelabel

Fix a bad /etc/fstab (the usual reason a server lands in “emergency mode”: a disk that was removed or renamed):

nano /etc/fstab      # comment out or correct the offending line
mount -a             # no output means every entry mounts

Stop a service from starting (say, one that hangs at startup or fills the disk):

systemctl disable --now my-service.service

Check a filesystem other than root (unmount it first, or work from emergency mode, where nothing else is mounted):

umount /data
fsck -f /dev/sdb1

Regain SSH access after a firewall rule shut you out:

ufw disable                         # Ubuntu
systemctl disable --now firewalld   # AlmaLinux / Rocky
# then fix the rules from a normal login and re-enable

Step 5: Reboot into the normal system

# AlmaLinux / Rocky: leave the chroot first
exit
# then, on every system:
exit          # or: reboot -f

Exiting the shell carries on with the normal boot on most systems. If yours doesn't, run reboot -f or press Reboot in the portal header. Your GRUB edit is already gone, so the next boot is an ordinary one.

Windows: the equivalent

There's no single-user mode on Windows. What comes closest is Safe Mode plus the Windows Recovery Environment. In the console, interrupt the boot twice in a row (power off at the Windows logo), and on the third boot Windows opens the recovery environment: Troubleshoot → Advanced options leads to Startup Settings (Safe Mode), Command Prompt and Startup Repair. A lost Administrator password can only be reset from there using a recovery image. If the account is locked out, see Windows account locked. For a lost password on a cloud instance, the portal's password reset gets you there directly.

Troubleshooting

  • I never see the GRUB menu. Bare metal hides it, and you get a second or two. Open the console before you reboot from the portal, then hold Shift from the instant the firmware screen clears. If the menu still won't appear, use rescue mode.
  • Rescue mode asks for a password I do not have. Reboot and go with init=/bin/bash (Ubuntu, Debian) or rd.break (AlmaLinux, Rocky) instead. Neither one asks.
  • “Read-only file system” when I run passwd. Step 3 was skipped. Remount read-write, then run passwd again.
  • The new password is refused after reboot (AlmaLinux, Rocky). The SELinux relabel didn't happen. Boot into rd.break once more, run touch /sysroot/.autorelabel and reboot. The relabel runs one time and takes a few minutes.
  • The keyboard does nothing in the console. Click inside the console window before typing. If your browser grabs the shortcut, send Ctrl+X with the console's virtual keyboard.
  • The GRUB edit screen shows a different layout. Cloud images and some distributions have a short linux line followed by an initrd line. The option still belongs at the end of the linux line, added before you press Ctrl+X.

Still stuck?

Open a support ticket, select the machine, and tell us what's on the console. When the boot loader itself is broken, rescue mode comes next, and we can talk you through it.

Built for production

Why teams stay with Netrouting

We connect you to the Internet using network engineers (and not order takers) and hardware and infrastructure that is built to last, so we can pick up where you left off when you need us.

  • Expert-Level Support Our staff is available 24 hours a day, 7 days a week to handle network administration and systems management issues as they occur.
  • Scalable Solutions Build whatever depth or breadth your infrastructure needs and then scale as required.
  • Enhanced Security Enable 2-factor authentication and also limit by IP address from the control panel to secure your account.
  • Cost-Efficient Infrastructure You will always receive the best value from your investment as you will be optimized for budget without any compromise on Quality.