Your server's first hour: a checklist

Ten things to do on a new Linux VPS before you put anything on it, in order, with commands for Ubuntu 24.04 and Debian 12.

A new server is on the internet from the moment it boots, and the bots find it within minutes. Spend the first hour on this list before you install anything else. Most steps take a few minutes and link to a longer guide if you want the detail.

The commands assume you're root, which you are on a new server. As a normal user, put sudo in front.

1. Update everything

bash
apt update && apt full-upgrade -y

If that pulled in a new kernel, you'll reboot at the end anyway.

2. Set the hostname and time zone

bash
hostnamectl set-hostname web-1
timedatectl set-timezone UTC

We like UTC on servers because logs from different machines line up. Use your own zone if you'd rather; timedatectl list-timezones lists them all.

3. Keep SSH on keys

Your server already logs you in with your key and refuses SSH passwords. Write that into your own SSH config so it stays that way, then give root a password with passwd for the serial console. Use SSH keys instead of a password has every command.

4. Create a normal user

Working as root all day makes every typo expensive. Make a user (here, deploy) and give it sudo. On Debian 12, run apt install -y sudo first if the command isn't there.

bash
adduser deploy
usermod -aG sudo deploy

Give the new user your keys so you can log in as it:

bash
install -d -m 700 -o deploy -g deploy /home/deploy/.ssh
install -m 600 -o deploy -g deploy ~/.ssh/authorized_keys /home/deploy/.ssh/

Try it from your computer with ssh [email protected], then run sudo -v to make sure sudo works.

5. Turn on a firewall

Allow SSH before you enable it, or you'll cut yourself off. Debian 12 doesn't ship ufw, so the first line installs it (on Ubuntu it's a no-op):

bash
apt install -y ufw
ufw allow OpenSSH
ufw enable

Set up a firewall with ufw explains the rest.

6. Install security updates automatically

bash
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

Say yes when it asks. Install security updates automatically covers automatic reboots and how to check it's running.

7. Slow down the password guessers

Even with passwords off, bots will fill your logs. Block brute-force attempts with fail2ban bans the addresses that keep trying.

8. Add swap on small plans

A bit of swap turns a memory spike into a slowdown instead of a dead database. See Add a swap file.

9. Check what's listening

bash
ss -tulpn

Each line is a port open to the network. On a fresh server you should see SSH on 22 and not much else. If something's there that you didn't install, find out what it is before going on.

10. Reboot and log back in

bash
reboot

Give it a minute, then connect again. If it comes back and your key still works, the basics are done. While you're at it, check that IPv6 works.

Where to next

For a website, Serve a site with nginx and HTTPS. For containers, Install Docker. If you plan to run a mail server, read Sending email: port 25 and Set reverse DNS first, because there's a block to lift. And set up backups before there's anything on the server you'd miss.

Be first when orders open

Join the waitlist and we'll send you one email when VPSNine launches. Pick a plan if you already know which one you want, and we'll size the first servers around it.