Hardening a fresh install
Our servers are unmanaged, so this is yours to do. It takes fifteen minutes and prevents most of the abuse reports we end up sending people.
1. Keys instead of passwords
Put your public key in ~/.ssh/authorized_keys, confirm you can log in
with it, then set PasswordAuthentication no and
PermitRootLogin prohibit-password in sshd_config and reload
SSH. Keep your current session open while you test the new one — that is what
the console is for if you lock yourself out anyway.
2. A firewall that denies by default
Allow what you actually serve and nothing else. nftables,
ufw or pf — whichever your system speaks. Databases,
caches and management interfaces should never be reachable from the internet; that is
how most compromised servers on any network got compromised.
3. Automatic security updates
Turn them on. unattended-upgrades on Debian and Ubuntu,
dnf-automatic on the Red Hat side. A server that is patched by a cron job
beats a server that is patched when you remember.
4. Fail2ban or an equivalent
It will not stop a determined attacker, but it keeps the noise out of your logs and off your CPU.
5. Backups, because we do not make them
This is the one people skip. We do not back up your server. Not the disks, not the databases, not by default and not quietly in the background. A failed disk or a bad command is yours to recover from, so put a backup somewhere that is not this machine and test restoring it once.
6. Watch your own service
We monitor the network and the hardware. We do not monitor your application, because we cannot see it. Point something at your own service so you hear about it before your customers do.
Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base