Basic security for a new VPS
New servers start getting automated login attempts soon after they go online. The steps below cover the basics. Commands are for Ubuntu and Debian.
1. Update everything
sudo apt update && sudo apt upgrade -y
2. Create your own user
Working as root all the time makes mistakes dangerous. Create a user with admin rights:
adduser alex
usermod -aG sudo alex
3. Set up SSH keys for that user
Follow Connect to your VPS over SSH to add your key, this time as the new user (ssh-copy-id alex@your-ip). Confirm you can log in as alex with the key before continuing.
4. Turn off password and root logins
Edit the SSH config:
sudo nano /etc/ssh/sshd_config
Set these lines (remove any # in front):
PermitRootLogin no
PasswordAuthentication no
Restart SSH:
sudo systemctl restart ssh
5. Enable the firewall
Allow SSH first, then the services you actually run:
sudo ufw allow OpenSSH
sudo ufw allow 'Nginx Full' # only if you run a website
sudo ufw enable
sudo ufw status
6. Ban brute-force attempts
sudo apt install -y fail2ban
sudo systemctl enable --now fail2ban
The default config protects SSH out of the box.
7. Install security updates automatically
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades
Keep it secure
- Only open firewall ports you're using.
- Don't run services as
rootwhen they don't need it. - Take regular off-server backups of anything important.
Still stuck? Open a ticket on Discord - run /ticket in any channel, pick a department, and include your Server ID or Invoice ID so we can jump straight in.