# Your server's first hour: a checklist

> Ten things to do on a new Linux VPS before you put anything on it, in order, with commands for Ubuntu 24.04 and Debian 12.

Source: https://vpsnine.com/help/first-hour-checklist · Updated: 2026-10-10

A new server is on the internet from the moment it boots, and the bots find it within minutes. Spend the first hour on this list before you install anything else. Most steps take a few minutes and link to a longer guide if you want the detail.

The commands assume you're root, which you are on a new server. As a normal user, put `sudo` in front.

## 1. Update everything

```bash
apt update && apt full-upgrade -y
```

If that pulled in a new kernel, you'll reboot at the end anyway.

## 2. Set the hostname and time zone

```bash
hostnamectl set-hostname web-1
timedatectl set-timezone UTC
```

We like UTC on servers because logs from different machines line up. Use your own zone if you'd rather; `timedatectl list-timezones` lists them all.

## 3. Keep SSH on keys

Your server already logs you in with your key and refuses SSH passwords. Write that into your own SSH config so it stays that way, then give root a password with `passwd` for the [serial console](https://vpsnine.com/help/serial-console). [Use SSH keys instead of a password](https://vpsnine.com/help/ssh-keys) has every command.

## 4. Create a normal user

Working as root all day makes every typo expensive. Make a user (here, `deploy`) and give it `sudo`. On Debian 12, run `apt install -y sudo` first if the command isn't there.

```bash
adduser deploy
usermod -aG sudo deploy
```

Give the new user your keys so you can log in as it:

```bash
install -d -m 700 -o deploy -g deploy /home/deploy/.ssh
install -m 600 -o deploy -g deploy ~/.ssh/authorized_keys /home/deploy/.ssh/
```

Try it from your computer with `ssh deploy@203.0.113.42`, then run `sudo -v` to make sure `sudo` works.

## 5. Turn on a firewall

Allow SSH *before* you enable it, or you'll cut yourself off. Debian 12 doesn't ship ufw, so the first line installs it (on Ubuntu it's a no-op):

```bash
apt install -y ufw
ufw allow OpenSSH
ufw enable
```

[Set up a firewall with ufw](https://vpsnine.com/help/firewall-with-ufw) explains the rest.

## 6. Install security updates automatically

```bash
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades
```

Say yes when it asks. [Install security updates automatically](https://vpsnine.com/help/automatic-security-updates) covers automatic reboots and how to check it's running.

## 7. Slow down the password guessers

Even with passwords off, bots will fill your logs. [Block brute-force attempts with fail2ban](https://vpsnine.com/help/fail2ban) bans the addresses that keep trying.

## 8. Add swap on small plans

A bit of swap turns a memory spike into a slowdown instead of a dead database. See [Add a swap file](https://vpsnine.com/help/add-swap).

## 9. Check what's listening

```bash
ss -tulpn
```

Each line is a port open to the network. On a fresh server you should see SSH on 22 and not much else. If something's there that you didn't install, find out what it is before going on.

## 10. Reboot and log back in

```bash
reboot
```

Give it a minute, then connect again. If it comes back and your key still works, the basics are done. While you're at it, [check that IPv6 works](https://vpsnine.com/help/ipv6-setup).

## Where to next

For a website, [Serve a site with nginx and HTTPS](https://vpsnine.com/help/nginx-and-https). For containers, [Install Docker](https://vpsnine.com/help/install-docker). If you plan to run a mail server, read [Sending email: port 25](https://vpsnine.com/help/open-port-25) and [Set reverse DNS](https://vpsnine.com/help/reverse-dns) first, because there's a block to lift. And set up [backups](https://vpsnine.com/help/backups-you-should-run) before there's anything on the server you'd miss.
