VPS Security Baseline: 10-Point Checklist Before You Go Live

Deploying a service without a solid security baseline invites compromise. This checklist gathers practical steps you can run on a fresh Ubuntu 24.04 instance before exposing any ports. Each item explains why it matters and gives a concrete command you can copy‑paste. Treat the list as a pre‑flight routine; skip nothing unless you fully understand the trade‑off.

Checklist

  • Update OS packages – Apply the latest security patches. Out‑of‑date libraries are a common entry point for attackers. Run sudo apt update && sudo apt full-upgrade -y and reboot if the kernel changes.
  • Configure firewall – Restrict inbound traffic to only services you need. Ubuntu ships with ufw which defaults to deny all. Enable it and open required ports, e.g., sudo ufw allow 22/tcp && sudo ufw enable.
  • Disable unused services – Each listening daemon expands the attack surface. List active sockets with ss -tuln, stop anything unnecessary, and mask it with systemctl mask service-name.
  • Enforce strong SSH settings – Switch to key‑based authentication, disable root login, and limit login attempts. Edit /etc/ssh/sshd_config to set PermitRootLogin no, PasswordAuthentication no, and MaxAuthTries 3, then reload the daemon.
  • Install fail2ban – Automatically ban IPs that trigger repeated authentication failures. After sudo apt install fail2ban, enable the default SSH jail or create a custom filter for your services.
  • Enable automatic security updates – Let the system install critical patches without manual intervention. Install unattended-upgrades and configure /etc/apt/apt.conf.d/50unattended-upgrades to apply "${distro_id}:${distro_codename}-security" updates.
  • Set up intrusion detection – Tools like AIDE or tripwire create a baseline of file hashes. Schedule a daily check; any unexpected change triggers an alert.
  • Restrict sudo access – Only grant sudo to users who truly need it. Use visudo to define precise command allowances and enable requiretty if applicable.
  • Audit container runtimes – If you run Docker or Podman, enable user‑namespace remapping, set a default seccomp profile, and avoid running containers as root. Verify with docker info --format '{{.SecurityOptions}}'.
  • Enable auditd logging – Capture system calls related to file access, privilege changes, and network activity. Install auditd, define rules in /etc/audit/rules.d/audit.rules, and forward logs to a remote syslog server for tamper‑proof storage.

Running this checklist before you open your service to the internet reduces the chance of a trivial compromise. Treat the output as a baseline; revisit it after any major software upgrade or configuration change.

sudo ufw allow 22/tcp && sudo ufw enable

Press Cmd K to search برای جستجوی سایت از Cmd+K استفاده کنید