A fresh VPS is a clean starting point, but it should not be treated as production-ready by default. A short hardening pass removes common risks before the first deployment.

Start with access control

  • Create a named operator account and use SSH keys instead of shared passwords.
  • Disable direct root login after confirming the operator account works.
  • Allow only the ports your application actually needs through the firewall.

Keep the baseline observable

Enable automatic security updates where appropriate, configure time synchronization, and make sure authentication and system logs are retained somewhere you can review them.

Test the recovery path

A backup that has never been restored is only an assumption. Take a snapshot, document the recovery steps, and verify that your application can be rebuilt without relying on an undocumented manual fix.