Servers & Hosting (Plesk, CloudPanel, Linux)
Basic Linux VPS Setup (Ubuntu/Debian)
Turn a brand-new, bare Ubuntu or Debian VPS into a properly configured, secure base server.
The Problem
A fresh VPS from most providers is just an OS with a root password — no firewall, no non-root user, no automatic security updates, and SSH wide open to the entire internet on the default port.
About this problem
Every major VPS provider hands you the same starting point: root access, a password, and nothing else configured. No firewall, no non-root user, no automatic security patching, and SSH open to the entire internet on port 22 — exactly what automated scanning bots are constantly looking for. This isn't a provider oversight; it's intentionally left for you to configure to your own needs.
This is the standard first step for literally any new VPS, before installing whatever application stack it's actually meant to run.
What's Included
- Creating a non-root user with sudo access and disabling root SSH login
- Setting up a firewall (UFW) with sensible default rules
- Enabling automatic security updates
- SSH key-based authentication in place of passwords
What's NOT Included
- Installing a specific web/application stack on top (separate service)
- Choosing or paying for the VPS
- Ongoing server maintenance after initial setup
How It Works
- Create a non-root user with sudo privileges and confirm it works before touching root access.
- Disable root login over SSH entirely once the new user is confirmed working.
- Install and configure UFW with rules for only the ports genuinely needed.
- Enable automatic security updates (unattended-upgrades or equivalent) so patches aren't missed.
- Set up SSH key-based authentication and disable password login once your key is confirmed working.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- Why shouldn't I just use the root account on my VPS?
- Using root for everyday tasks means any mistake or compromised process has full system access immediately — a sudo-capable regular user adds a meaningful safety buffer.
- Is a fresh VPS safe to leave for a day before configuring it?
- Not ideally — automated scanning of new IP ranges happens constantly, so basic hardening (firewall, SSH settings) is worth doing as close to first boot as practical.
- What firewall should I use on a Linux VPS?
- UFW is the most common choice for Ubuntu/Debian systems — it's a simpler front-end over iptables that covers the vast majority of basic hosting firewall needs.
- Should I disable password login for SSH?
- Yes, once key-based authentication is confirmed working — passwords are brute-forceable, while a properly generated SSH key effectively isn't.
- What happens if I lose my SSH key after disabling password login?
- You'd need your VPS provider's console/recovery access to get back in, which is why it's important to confirm your key works reliably before fully disabling password access.
- Do I need automatic updates on a VPS?
- Strongly recommended for security patches at minimum — unattended major upgrades carry more risk and are usually left manual, but security-only automatic updates are a sensible default.