Your VPS has just been delivered. Before installing anything, spend fifteen minutes on these basics: they close the doors that bots start probing within minutes, and they will save you a lot of trouble later. Commands target Ubuntu 24.04 and Debian 12; AlmaLinux and Rocky Linux equivalents are given where they differ.
1. Connect over SSH
The IP address and root password of your VPS are shown in your client area at me.nvhcloud.com.
- Windows 10 and 11: the SSH client is built in. Open PowerShell or Windows Terminal.
- macOS and Linux: open the Terminal.
ssh root@YOUR_VPS_IP
On the first connection, SSH shows the server fingerprint and asks for confirmation: type yes. The password is not displayed while you type, which is normal.
Connection timed out usually means the VPS is still installing: wait a minute. With Permission denied, check the password, and watch out for copy-paste adding a trailing space.2. Update the system
The installation image is a few weeks old: security fixes have almost certainly been released since.
# Debian / Ubuntu
apt update && apt upgrade -y && apt autoremove -y
# AlmaLinux / Rocky Linux
dnf upgrade -y
If the kernel was updated, reboot to apply it with reboot. On Debian and Ubuntu, the file /var/run/reboot-required exists when a reboot is needed.
3. Turn on automatic security updates
A server exposed to the Internet should not wait for you to remember updates. This package installs security fixes, and only those, every day:
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades
Answer Yes. On AlmaLinux and Rocky Linux, the equivalent package is dnf-automatic.
4. Hostname and time zone
hostnamectl set-hostname web01
timedatectl set-timezone Europe/London
timedatectl
A clear name helps you find your way in logs and alerts once you run several servers. Pick the time zone you work in (timedatectl list-timezones lists them all) so scheduled tasks and logs are not shifted by an hour or two.
5. Create a user with sudo rights
Working as root all the time means a single typo can affect the whole system. Create a personal account that gets administrator rights on demand with sudo:
adduser alex
usermod -aG sudo alex # Debian / Ubuntu
usermod -aG wheel alex # AlmaLinux / Rocky
Replace alex with the name of your choice.
6. Switch to SSH keys
An SSH key is far safer than a password, and more convenient: nothing left to type. On your computer, not on the server:
ssh-keygen -t ed25519
Accept the default path. A passphrase protects the key if your computer is stolen. Then copy the public key to the server:
# macOS / Linux
ssh-copy-id alex@YOUR_VPS_IP
# Windows (PowerShell)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh alex@YOUR_VPS_IP "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"
Test it: ssh alex@YOUR_VPS_IP should log you in without a password. Once it does, disable passwords and root login by following securing SSH.
7. Enable the firewall
apt install -y ufw
ufw default deny incoming
ufw default allow outgoing
ufw allow OpenSSH
ufw enable
The SSH port must be allowed before ufw enable. Then open the ports your project needs, and nothing else: see configuring UFW.
8. Add swap on small servers
On a 1 or 2 GB VPS, a memory spike can get a process killed, very often the database. A swap file acts as a buffer. First check that none exists with free -h, then:
fallocate -l 2G /swapfile
chmod 600 /swapfile
mkswap /swapfile && swapon /swapfile
echo '/swapfile none swap sw 0 0' >> /etc/fstab
sysctl vm.swappiness=10
echo 'vm.swappiness=10' > /etc/sysctl.d/99-swap.conf
With swappiness at 10, the system only uses swap as a last resort. Swap prevents crashes but does not replace memory: if it is used all the time, the VPS is too small.
9. Check the server
uptime # load and uptime
free -h # memory and swap
df -h # disk space
ss -tulpn # open ports and the programs using them
The last command is the most useful: it shows everything listening on the network. On a new server, you should only see SSH.
10. What next?
Your server is ready. Depending on your project:
- A website: Nginx and HTTPS (in French), then WordPress.
- Containers: Docker and Docker Compose.
- A game server: FiveM, Minecraft or Rust.
- In every case: off-server backups.
Frequently asked questions
How do I connect to my VPS from Windows?
I lost SSH access to my VPS, what can I do?
Should I change the default SSH port?
Which Linux distribution should I choose?
Related
Securing SSH on a VPS
Keys only, root disabled and Fail2ban, without locking yourself out.
Configuring the UFW firewall
An allow-list firewall and the ports to open for each use.