首页 / Guides / VPS Security Hardening Checklist — 12 Steps After the First Login
How-to

VPS Security Hardening Checklist — 12 Steps After the First Login

A practical hardening checklist: keys over passwords, firewall defaults, automatic patches, fail2ban, audit surface and backups you actually test.

长文正文为英文。页头、目录与结账已翻译。

NovaVPS no-KYC abstract: shield and dissolving ID card

Identity and access

  1. Add your SSH public key, then disable password authentication for root.
  2. Create a named sudo user; reserve root for console/rescue only.
  3. Enable 2FA on the hosting panel — the panel is part of your attack surface too.

VPS from $8.50/mo. Email, a 12-character password, then a crypto invoice.

Launch now

Network surface

  1. Default-deny firewall: allow 22 (or your moved port), 80/443, and each service you actually run.
  2. Close the panel ports you do not use; bind admin interfaces to localhost or a VPN.
  3. Install fail2ban (or sshguard) — log noise drops by an order of magnitude.

System and data

  1. Turn on unattended security upgrades for the base system.
  2. Schedule snapshots plus an off-box backup; an untested backup is a rumor, not a backup.
  3. For sensitive data at rest, add a LUKS container opened after boot — see the encrypted VPS guide.
Does NovaVPS harden the server for me?

No — you get root, which means the hardening decisions (and their benefits) are yours. The checklist above is the standard baseline.

Is a VPS with password login unsafe by default?

It is weaker: password brute-force noise starts within minutes of a public IP. Keys first is the single highest-value step.

Do I need antivirus on a Linux VPS?

Rarely for the OS itself; run malware scanners on the content you serve (e.g. uploads) if you accept files from users.

Ready to launch?

Configure a VPS or dedicated server, set a password, then pay the invoice.

Network

Edge RTT

Uptime · 36h

Complaints · 36h

Pick a city