Your First 30 Minutes on a New VPS
A practical checklist for the first half hour on a fresh VPS — logging in, updating, creating a user, SSH keys, a firewall, time zone, swap and automatic security updates.
On this page
- Minute 0–5: Log in and update
- Minute 5–10: Create a regular user
- Minute 10–15: Set up SSH keys
- Minute 15–20: Turn on a firewall
- Minute 20–23: Set the time zone and hostname
- Minute 23–26: Add swap (for small plans)
- Minute 26–30: Automatic security updates
- Before you install anything else
- What’s next
- The checklist
- Summary
A brand-new VPS is a clean slate — and, from the moment it gets a public IP address, a target for automated login attempts. The first half hour is when you set the foundations that keep it secure and pleasant to work with. This checklist assumes Ubuntu (22.04 or 24.04) or Debian; the ideas apply everywhere.
Minute 0–5: Log in and update
Your provider gives you the server’s IP address and either a root password or a way to add your SSH key. Log in:
ssh root@YOUR_SERVER_IP
If you can’t reach SSH at all, most control panels offer a web VNC console that works even when networking is misconfigured — Kerit Cloud’s VPS panel includes one.
Then update everything:
apt update && apt upgrade -y
If a kernel update was installed, reboot now (reboot) and log back in, so you start on the latest kernel.
Minute 5–10: Create a regular user
Working as root all the time makes mistakes more costly. Create a user with sudo rights:
adduser deploy
usermod -aG sudo deploy
Pick your own username. From now on you’ll log in as this user and use sudo for administrative commands.
Minute 10–15: Set up SSH keys
Passwords can be guessed; SSH keys practically can’t. On your own computer (not the server), create a key if you don’t have one:
ssh-keygen -t ed25519 -C "you@example.com"
Copy it to the server for your new user:
ssh-copy-id deploy@YOUR_SERVER_IP
Open a new terminal and confirm you can log in with the key:
ssh deploy@YOUR_SERVER_IP
Keep your existing root session open until you’ve confirmed the key works — it’s your safety net.
Now turn off password logins and direct root login. Edit the SSH configuration:
sudo nano /etc/ssh/sshd_config
Set:
PasswordAuthentication no
PermitRootLogin no
On recent Ubuntu releases, files in /etc/ssh/sshd_config.d/ can override these settings — cloud images sometimes include one that re-enables passwords. Check that directory and make sure nothing there sets PasswordAuthentication yes. Then restart SSH:
sudo systemctl restart ssh
Test again from a new terminal before closing your root session. Securing a fresh Ubuntu VPS covers this in more depth.
Minute 15–20: Turn on a firewall
Ubuntu includes UFW, a friendly front end for the firewall. Allow SSH first, then enable it:
sudo ufw allow OpenSSH
sudo ufw enable
sudo ufw status verbose
Add rules only for services you actually run:
sudo ufw allow 80/tcp # HTTP
sudo ufw allow 443/tcp # HTTPS
If your provider offers an edge firewall in front of the VPS, use both: the edge firewall drops traffic before it reaches your server, and UFW protects you if an edge rule is ever misconfigured. See using an edge firewall and port policies.
Minute 20–23: Set the time zone and hostname
Logs are much easier to read with the right time zone:
sudo timedatectl set-timezone UTC # or e.g. Asia/Kolkata, America/New_York
timedatectl
Many administrators keep servers on UTC so logs from different machines line up. Give the server a meaningful name too:
sudo hostnamectl set-hostname web-01
Minute 23–26: Add swap (for small plans)
Swap is disk space the system can use when RAM runs out. It’s slower than memory, but it can prevent processes from being killed during a brief spike. On a 2–4 GB VPS, a small swap file is sensible:
sudo fallocate -l 2G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
Swap is a safety net, not extra RAM. If your server swaps constantly, it needs more memory.
Minute 26–30: Automatic security updates
Unattended upgrades install security patches automatically:
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades
This covers security updates for installed packages, which closes the most common way servers get compromised: known vulnerabilities left unpatched.
Before you install anything else
Take a moment to:
- Note your server details — IP addresses, your user, which ports are open — somewhere safe.
- Check backups — Kerit Cloud VPS plans include daily automated off-site backups with one-click restore; confirm they’re enabled, and take a manual snapshot now that the base setup is done. See VPS backups and snapshots.
- Install basic tools —
sudo apt install -y htop curl git unzipcovers most day-to-day needs.
What’s next
With the foundations in place, install what you came for:
- Docker and Docker Compose for containerised apps.
- Nginx with free SSL for websites and APIs.
- PM2 for several bots.
- Monitoring so you know when something goes wrong.
The checklist
- [ ] Logged in, updated and rebooted
- [ ] Non-root user with sudo
- [ ] SSH key login working
- [ ] Password and root SSH login disabled
- [ ] UFW enabled with only needed ports open
- [ ] Time zone and hostname set
- [ ] Swap added on small plans
- [ ] Unattended security upgrades enabled
- [ ] Backups confirmed and a snapshot taken
Summary
In your first 30 minutes on a VPS: update the system, create a sudo user, switch to SSH keys and disable password and root login (checking sshd_config.d for overrides), enable UFW with only the ports you need, set the time zone and hostname, add a small swap file on small plans, turn on unattended security upgrades, and confirm your backups. Everything you install afterwards sits on a solid, secure base.