I don't use a VPS, I run my own physical server at home. It doesn't require a shiny new state-of-the-art computer. I use a NUC a few years old, and I have used a converted chromebook in the past. I prefer Debian, because it just works and I'm familiar with it. I do pretty much the same things as above, plus installing tailscale or zerotier for access from outside my home LAN. I don't use fail2ban, but I do use pi-hole. My router does the firewall jobs. I use sshfs to mount the data drives to my other devices. My needs are rather simple, I'm not running a website, just a file and pi-hole server. I'm probably not the target audience for the OP.
Did I miss anything?
For server I would also set up aide, to detect intrusions.
it depends on you threat model.
3. Set up SSH key login
3. Set up SSH key login
4. Disable root login and password login in /etc/ssh/sshd_config
5. Change the default SSH port (optional)
6. Turn on the firewall (UFW or firewalld) and open only the ports you need
I would setup a whitelist of allowed ip's that are allowed to access the ssh port. Leased privilege principle.
7. Install fail2ban to block brute force attempts
I would setup fail2ban for your apache or Nginx log files and smtp and imap if you are also running a mailserver.
8. Set the correct timezone and enable automatic security updates
9. Set up regular backups or snapshots
I update manually once a month or so, this is a choice but something I wouldn't do myself.
10. Install basic monitoring (htop, netdata, or similar)
I don't do this, as I'm not running a business and I have a backup for the vps for the important things like a backup mailhost.
I don't use a VPS, I run my own physical server at home. It doesn't require a shiny new state-of-the-art computer.
I do too but if you want to host your own mail, this is not really an option. I have some stuff running from home in a separate vlan, so I can access my Jellyfin and Plex server from home but I also have an IDS active with signatures active scanning and blocking suspicious activity.
For server I would also set up aide, to detect intrusions.
it depends on you threat model.
I used to run chkrootkit and things like that on my vpses, since I'm the only one using the vps I found it overkill and I stopped using it a long time back. At work we still use it on all of our systems though.
Did I miss anything?
I would mostly use containers where possible and reverse proxy those and via Apache or Nginx, unless you have a specific reason not to.
What do you do on your own servers? Also, do you prefer Ubuntu, Debian or AlmaLinux for a VPS, and why?
I was using Debian, but I recently switched my vpses to Fedora because updating from one major version to the next is well supported and it's close enough to RHEL. Because a RHEL version is based on a specific version of Fedora and maintained by Redhat for a longer release cycle. If I ever wanted to make the switch back to CentOS or another RHEL clone I have that option without having to change anything about my setup.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | "n" days to learn Linux. Not just stupid copy pasting and breaking homelab and using LLM to get by... | 0 | 8.01 | 05-10-2026 |
| 2 | Suggested Distro for GPD MicroPC 2 (completely new user) | 0 | 21.11 | 05-10-2026 |
| 3 | Кухня курса: как я собираю онлайн-курс на нейросетях — по шагам | 0 | 14.4 | 29-09-2026 |
| 4 | Linux Kernel Developers Consider Adding AGENTS.md To Help Guide AI/LLM Agents | 0 | 5.48 | 25-09-2026 |
| 5 | Setting Up a K3s Kubernetes Cluster on NVIDIA DGX Spark with Full GPU Support | 0 | 8.34 | 21-06-2026 |
| 6 | An SEO guide for service businesses | 0 | 6.55 | 31-03-2026 |
| 7 | A Beginner’s Guide to Kubernetes Operators and How They Work | 0 | 8.1 | 27-09-2026 |
| 8 | Wisp Makes It Easier To Manage Btrfs Snapshots From The GNOME Desktop | 0 | 7.65 | 26-09-2026 |
| 9 | Adventures in Streaming: What to watch if you're in your hostage era | 0 | 8.4 | 25-09-2026 |
| 10 | Claude Code Tips and Tricks: 10 Best Practices Every Developer Should Know | 0 | 19.28 | 24-08-2026 |