VPS Security Baseline: 10-Point Checklist Before You Go Live
Deploying a service without a solid security baseline invites compromise. This checklist gathers practical steps you can run on a fresh Ubuntu 24.04 instance before exposing any ports. Each item explains why it matters and gives a concrete command you can copy‑paste. Treat the list as a pre‑flight routine; skip nothing unless you fully understand the trade‑off.
Checklist
- Update OS packages – Apply the latest security patches. Out‑of‑date libraries are a common entry point for attackers. Run
sudo apt update && sudo apt full-upgrade -yand reboot if the kernel changes. - Configure firewall – Restrict inbound traffic to only services you need. Ubuntu ships with
ufwwhich defaults to deny all. Enable it and open required ports, e.g.,sudo ufw allow 22/tcp && sudo ufw enable. - Disable unused services – Each listening daemon expands the attack surface. List active sockets with
ss -tuln, stop anything unnecessary, and mask it withsystemctl mask service-name. - Enforce strong SSH settings – Switch to key‑based authentication, disable root login, and limit login attempts. Edit
/etc/ssh/sshd_configto setPermitRootLogin no,PasswordAuthentication no, andMaxAuthTries 3, then reload the daemon. - Install fail2ban – Automatically ban IPs that trigger repeated authentication failures. After
sudo apt install fail2ban, enable the default SSH jail or create a custom filter for your services. - Enable automatic security updates – Let the system install critical patches without manual intervention. Install
unattended-upgradesand configure/etc/apt/apt.conf.d/50unattended-upgradesto apply"${distro_id}:${distro_codename}-security"updates. - Set up intrusion detection – Tools like
AIDEortripwirecreate a baseline of file hashes. Schedule a daily check; any unexpected change triggers an alert. - Restrict sudo access – Only grant sudo to users who truly need it. Use
visudoto define precise command allowances and enablerequirettyif applicable. - Audit container runtimes – If you run Docker or Podman, enable user‑namespace remapping, set a default seccomp profile, and avoid running containers as root. Verify with
docker info --format '{{.SecurityOptions}}'. - Enable auditd logging – Capture system calls related to file access, privilege changes, and network activity. Install
auditd, define rules in/etc/audit/rules.d/audit.rules, and forward logs to a remote syslog server for tamper‑proof storage.
Running this checklist before you open your service to the internet reduces the chance of a trivial compromise. Treat the output as a baseline; revisit it after any major software upgrade or configuration change.
sudo ufw allow 22/tcp && sudo ufw enable