Setup & operation
How do I secure a new VPS?
Five steps cover the overwhelming majority of real-world compromises: key-based SSH with password authentication disabled, no direct root login, a default-deny firewall, unattended security updates, and fail2ban or an equivalent. Together they take about ten minutes and eliminate essentially all automated attacks.
Automated attacks begin within minutes of an address going live. They are not targeted at you; they are targeted at everyone, continuously. Password authentication on port 22 is what they are looking for.
The step people skip is the firewall. Default-deny inbound, with explicit allows only for what you actually serve, protects you from the service you forgot was listening — which is how most real intrusions begin.
- ssh-keygen -t ed25519, upload the public key, then set PasswordAuthentication no
- PermitRootLogin no; use a normal user with sudo
- nftables or ufw: default deny inbound, allow 22, 80, 443 and nothing else
- Enable unattended-upgrades so security patches land without you
- Install fail2ban, or move SSH behind WireGuard so it is not exposed at all
- Take a snapshot once it is configured — that becomes your known-good state
See also: fail2ban
7 answers in Setup & operation
- How do I connect to a VPS with SSH? Run ssh root@your-server-ip from any terminal on macOS, Linux or Windows 10 and later. Use the key you supplied at provisioning, or the password email…
- How do I stop SSH brute-force attacks? Disable password authentication entirely — brute force against key-based SSH is not possible. Add fail2ban to reduce log noise, and consider moving SS…
- How do I set up a firewall on a VPS? Use nftables on modern Linux, or ufw as a friendlier front end. Set the default inbound policy to drop, allow established and related connections, the…
- Can I install any operating system on a VPS? On KVM, yes. OnionVPS provides templates for Ubuntu, Debian, AlmaLinux, Rocky, Fedora, Arch, Alpine, NixOS, FreeBSD, OpenBSD, Windows Server, Proxmox …
- Can I upload my own ISO? Yes, on every plan, at no cost and with no approval step. Upload the ISO from the panel or point us at a URL, attach it as virtual media, and boot fro…
- What is KVM virtualisation? KVM (Kernel-based Virtual Machine) is full hardware virtualisation built into the Linux kernel, using processor extensions to run each guest with its …