Kingsfordweg 151, 1043GR Amsterdam, The Netherlands ● 24/7 support — support@novogara.com
Knowledge base

Hardening a fresh install

Our servers are unmanaged, so this is yours to do. It takes fifteen minutes and prevents most of the abuse reports we end up sending people.

1. Keys instead of passwords

Put your public key in ~/.ssh/authorized_keys, confirm you can log in with it, then set PasswordAuthentication no and PermitRootLogin prohibit-password in sshd_config and reload SSH. Keep your current session open while you test the new one — that is what the console is for if you lock yourself out anyway.

2. A firewall that denies by default

Allow what you actually serve and nothing else. nftables, ufw or pf — whichever your system speaks. Databases, caches and management interfaces should never be reachable from the internet; that is how most compromised servers on any network got compromised.

3. Automatic security updates

Turn them on. unattended-upgrades on Debian and Ubuntu, dnf-automatic on the Red Hat side. A server that is patched by a cron job beats a server that is patched when you remember.

4. Fail2ban or an equivalent

It will not stop a determined attacker, but it keeps the noise out of your logs and off your CPU.

5. Backups, because we do not make them

This is the one people skip. We do not back up your server. Not the disks, not the databases, not by default and not quietly in the background. A failed disk or a bad command is yours to recover from, so put a backup somewhere that is not this machine and test restoring it once.

6. Watch your own service

We monitor the network and the hardware. We do not monitor your application, because we cannot see it. Point something at your own service so you hear about it before your customers do.


Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base