Production Linux: Secure and Maintain Your Own VPS
A 10-post series covering the full lifecycle of a production Linux VPS — from first login to disaster recovery.
A 10-post series covering the full lifecycle of a production Linux VPS — from first login to disaster recovery.
Set up a DigitalOcean droplet from scratch: first SSH connection, deploy user, UFW baseline, and unattended upgrades.
Lock down SSH access with ed25519 keys, disable root login, and remove unused authentication methods.
Configure UFW rules, build a fail2ban jail for Caddy access logs, and escalate bans for repeat offenders with the recidive jail.
Why Docker bypasses your UFW rules, how to fix it, and container hardening practices that matter on a shared VPS.
Add security headers, rate limiting, and server identity removal to your Caddy configuration.
Tune kernel parameters with sysctl and sandbox services with systemd to reduce your VPS attack surface.
Manage .env files, encrypt secrets with Ansible Vault, and rotate credentials without downtime.
Configure automatic security patches, detect stale services with needrestart, and keep logs and Docker images from filling your disk.
Set up lightweight monitoring and alerting for a solo-developer VPS, plus a post-incident checklist.
Automate backups, test restores, and build a disaster recovery runbook for your VPS.