Guide

Secure a new VPS in 10 minutes

Beginner10 min readUpdated June 18, 2026
Short answer

Five changes eliminate essentially every automated attack against a new server: key-based SSH with passwords disabled, no direct root login, a default-deny firewall covering both IPv4 and IPv6, unattended security updates, and fail2ban. Together they take about ten minutes and matter more than any provider feature.

01 Generate and install an SSH key

Do this from your own machine, not the server. Ed25519 keys are shorter and faster than RSA and are supported everywhere that matters.

ssh-keygen -t ed25519 -C "onionvps-$(date +%Y%m)"
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@YOUR_SERVER_IP

02 Create a non-root user

Working as root all the time removes a useful safety net and makes every mistake maximally expensive.

adduser --gecos "" ops
usermod -aG sudo ops
rsync --archive --chown=ops:ops ~/.ssh /home/ops

03 Harden the SSH daemon

Disable password authentication entirely — brute force against key-only SSH is not possible. Keep a second terminal connected while you do this, so a mistake does not lock you out.

cat >/etc/ssh/sshd_config.d/99-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin no
KbdInteractiveAuthentication no
AllowUsers ops
EOF
sshd -t && systemctl reload ssh

04 Set a default-deny firewall

Cover IPv6 as well as IPv4. Every OnionVPS instance has a routed /64, so a v4-only ruleset leaves every service publicly reachable over v6.

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80,443/tcp
ufw enable
ufw status verbose   # confirm IPv6 shows as enabled

05 Turn on automatic security updates

Unattended upgrades close the window between a patch being published and you noticing it exists.

apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

06 Install fail2ban and take a snapshot

fail2ban mostly reduces log noise once passwords are disabled, but it is cheap. Then snapshot the configured state — that becomes your known-good baseline.

apt install -y fail2ban && systemctl enable --now fail2ban

Frequently asked questions

Should I change the SSH port?

It is noise reduction rather than security, but it is effective noise reduction — the vast majority of scanners only try port 22. Combined with key-only authentication, the residual risk is negligible either way.

What if I lock myself out?

Use the out-of-band VNC console in the control panel. It attaches to the virtual serial console and works with no network at all.