For a step-by-step walkthrough of the first steps, with each command explained, see First Steps on a New Linux Server.
Priority 1 — Do these immediately
1. Update all packages
apt update && apt full-upgrade -y # Debian / Ubuntu
dnf update -y # AlmaLinux / Rocky
2. Create a non-root admin user
adduser deploy
usermod -aG sudo deploy
3. Configure SSH key authentication
On your local machine:
ssh-keygen -t ed25519 -C "my-vps-key"
ssh-copy-id deploy@YOUR_VPS_IP
4. Harden SSH configuration
Put the settings in their own file. The 00- prefix matters: SSH uses the first value it reads, and some images ship a 50-cloud-init.conf that turns password logins back on.
cat > /etc/ssh/sshd_config.d/00-hardening.conf <<'CONF'
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
AllowUsers deploy
MaxAuthTries 3
CONF
sshd -t && systemctl restart ssh # "sshd" on AlmaLinux / Rocky
sshd -T | grep -Ei '^(passwordauthentication|permitrootlogin)'
Keep your current session open and test a new login as deploy before you close it.
5. Enable and configure UFW
See the Configuring a software firewall article for full details.
apt install -y ufw # not installed by default on Debian
ufw default deny incoming
ufw default allow outgoing
ufw allow ssh
ufw enable
Priority 2 — Highly recommended
6. Install Fail2ban
apt install -y fail2ban python3-systemd
printf '[sshd]\nenabled = true\nbackend = systemd\n' > /etc/fail2ban/jail.d/sshd.local
systemctl enable fail2ban
systemctl restart fail2ban
Fail2ban watches auth logs and automatically blocks IPs after repeated failed login attempts.
7. Enable automatic security updates
apt install unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades
8. Disable unused services
systemctl list-units --type=service --state=running
# Disable anything you don't need, e.g.:
systemctl disable --now avahi-daemon
Priority 3 — For production workloads
9. Configure log shipping
Ship logs to an external service (Papertrail, Logtail, Loki) so you have an audit trail even if the VPS is compromised.
10. Set up a vulnerability scanner
Lynis is a free, open-source security audit tool:
apt install lynis
lynis audit system
Review the suggestions in the report and address items rated [WARNING] first.