How to secure your VPS in 15 minutes
Bots start scanning a new server within minutes after it goes online. These steps close the most common ways in and work on Ubuntu and Debian.
1. Install updates
apt update && apt upgrade -yTurn on automatic security updates:
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades2. Log in with a key, not a password
An SSH key is practically impossible to guess. How to create one and disable password login is explained in connect via SSH.
3. Enable a firewall
UFW blocks all incoming connections except the ones you allow. Allow SSH first, otherwise you lock yourself out:
apt install -y ufw
ufw allow OpenSSH
ufw enable
ufw statusOpen only the ports you need. For WireGuard:
ufw allow 51820/udpFor a website:
ufw allow 80/tcp
ufw allow 443/tcp4. Install fail2ban
fail2ban blocks IP addresses that fail to log in many times:
apt install -y fail2ban
systemctl enable --now fail2ban
fail2ban-client status sshdSSH protection is active right after installation.
5. Do not work as root
Create a regular user with admin rights:
adduser admin
usermod -aG sudo adminCopy your SSH key to that user, log in with it and run admin commands with sudo.
6. Keep copies of your data elsewhere
OBLAKO does not back up servers. Copy important data to your computer or cloud storage regularly, for example with rsync or restic.
7. Watch the load
The Metrics tab in the panel shows CPU, memory, disk and network charts. A sudden load spike with no reason can be a sign of a compromise.
Locked out?
If a firewall rule cut your SSH access, open the Console tab in the panel and fix the rules. See managing your server.