01 Generar e instalar una clave SSH
Do this from your own machine, not the server. Ed25519 keys are shorter and faster than RSA and are supported everywhere that matters.
ssh-keygen -t ed25519 -C "onionvps-$(date +%Y%m)"
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@YOUR_SERVER_IP 02 Crear un usuario no root
Working as root all the time removes a useful safety net and makes every mistake maximally expensive.
adduser --gecos "" ops
usermod -aG sudo ops
rsync --archive --chown=ops:ops ~/.ssh /home/ops 03 Endurecer el demonio SSH
Disable password authentication entirely — brute force against key-only SSH is not possible. Keep a second terminal connected while you do this, so a mistake does not lock you out.
cat >/etc/ssh/sshd_config.d/99-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin no
KbdInteractiveAuthentication no
AllowUsers ops
EOF
sshd -t && systemctl reload ssh 04 Configurar un firewall con denegación por defecto
Cover IPv6 as well as IPv4. Every OnionVPS instance has a routed /64, so a v4-only ruleset leaves every service publicly reachable over v6.
ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80,443/tcp
ufw enable
ufw status verbose # confirm IPv6 shows as enabled 05 Activar actualizaciones automáticas de seguridad
Unattended upgrades close the window between a patch being published and you noticing it exists.
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades 06 Instalar fail2ban y tomar una instantánea
fail2ban mostly reduces log noise once passwords are disabled, but it is cheap. Then snapshot the configured state — that becomes your known-good baseline.
apt install -y fail2ban && systemctl enable --now fail2ban