A brand-new server is online the moment it boots, and so are the bots that scan the internet for weak logins. The steps below close the obvious doors. Do them before you install anything else.
1. Use an SSH key instead of a password
On your own computer, create a key if you don’t have one:
ssh-keygen -t ed25519 -C "your-laptop"
Copy it to the server using the port and address from your welcome email:
ssh-copy-id -p YOUR_SSH_PORT root@YOUR_SERVER_ADDRESS
Log in again. It shouldn’t ask for the server password this time.
2. Update everything
apt update && apt upgrade -y
3. Create your own user
Day-to-day work as root makes every mistake a big one. Create a user with sudo rights and give it your key:
adduser dev
usermod -aG sudo dev
rsync --archive --chown=dev:dev ~/.ssh /home/dev
Open a second terminal and check you can log in as that user before going further:
ssh -p YOUR_SSH_PORT dev@YOUR_SERVER_ADDRESS
4. Turn off password and root logins
Ubuntu 24.04 reads extra SSH settings from /etc/ssh/sshd_config.d/. Create a file there:
sudo tee /etc/ssh/sshd_config.d/10-hardening.conf > /dev/null <<'EOF'
PasswordAuthentication no
PermitRootLogin no
EOF
sudo sshd -t && sudo systemctl restart ssh
sshd -t checks the configuration first, so a typo doesn’t take SSH down. Test a new login from another terminal before closing the old one.
5. Switch on the firewall
Allow SSH first, then enable the firewall. If your SSH port isn’t 22, allow that port number instead of OpenSSH:
sudo ufw allow OpenSSH
sudo ufw enable
sudo ufw status
Add rules later as you add services, for example sudo ufw allow 443/tcp for a website.
6. Install security updates automatically
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades
Choose Yes. Security patches now install on their own every day.
7. Add swap on small servers
With 1 GB of memory, a package install or a build can run out of RAM. A swap file gives it room to breathe:
sudo fallocate -l 1G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
free -h
Optional: ban repeat offenders
fail2ban watches the SSH log and blocks addresses that keep failing to log in. On Ubuntu it protects SSH as soon as it’s installed:
sudo apt install -y fail2ban
sudo fail2ban-client status sshd
What you have now
- Key-only SSH, with no root login
- A personal user with
sudo - A firewall that only lets in what you allow
- Security updates that install themselves
- Swap so small plans don’t fall over
Next, give the server something to do. A Discord bot is a good first project.
How we made this: drafted with AI assistance, then edited. Technical testing is pending.