Five first steps to secure a new Ubuntu VPS

Five first steps to secure a new Ubuntu VPS

A brand new server is a blank slate. If you've chosen a self-managed VPS, these five steps will put you in a much stronger position before you install anything else. All of the commands below are run as root over SSH.

1. Install the latest updates

Start by bringing every package up to date:

apt update && apt upgrade -y

2. Create a user for everyday work

Working as root all the time makes mistakes more costly. Create a normal user and give it sudo rights:

adduser deploy
usermod -aG sudo deploy

If you log in with an SSH key, copy it to the new user:

rsync --archive --chown=deploy:deploy ~/.ssh /home/deploy

Open a second terminal and check you can log in with ssh deploy@your-server-ip before you go any further.

3. Turn on the firewall

Ubuntu comes with UFW, a simple firewall. Allow SSH first so you don't lock yourself out, then switch it on:

ufw allow OpenSSH
ufw enable

When you add a website later, allow web traffic with ufw allow 80 and ufw allow 443.

4. Install security updates automatically

Unattended upgrades installs security fixes for you:

apt install unattended-upgrades
dpkg-reconfigure --priority=low unattended-upgrades

5. Stop root logging in over SSH

Once you've confirmed your new user can log in and use sudo, you can stop root logging in over SSH. On CloudNest servers the SSH login settings are in /etc/ssh/sshd_config.d/00-cloudnest.conf. Change the PermitRootLogin line to:

PermitRootLogin no

Then restart SSH with systemctl restart ssh. Keep your existing session open and test logging in again from a new terminal before you close it.

That's it: your server is updated, firewalled, patching itself and much harder to break into. Prefer us to take care of all of this for you? Take a look at our Fully Managed VPS plans.