A VPS gives you a whole Linux server with root access, and with it the job of keeping that server secure and fast. This guide is a practical checklist for your own VPS or dedicated server: what to lock down on day one, what to monitor, and which tuning changes actually help.
Update the system, log in with SSH keys only, use a non-root sudo user, and allow only the ports you need through a firewall. Add fail2ban, automatic security updates, HTTPS with Let's Encrypt and off-server backups you have test-restored. Then measure before you tune: most speed gains come from caching, a right-sized database buffer and removing services you don't use.
Everything here applies to a VPS or dedicated server where you have root access. On Domain India shared hosting (cPanel, DirectAdmin, Webuzo) the server is managed for you and customers can't change its firewall, web server or PHP configuration. For shared hosting, see what to do if your website has been hacked and my website is slow.
1. Start from a supported operating system
Security starts with an OS that still receives fixes. In 2026 that means a current long-term-support release such as Ubuntu 24.04 LTS, Debian 12 or 13, AlmaLinux 9 or 10, or Rocky Linux 9 or 10. CentOS Linux has reached end of life and gets no security updates; if a server still runs it, plan a migration to AlmaLinux or Rocky Linux.
Update everything right after the first login, and reboot if the kernel changed:
# Ubuntu / Debian
sudo apt update && sudo apt full-upgrade -y
# AlmaLinux / Rocky Linux
sudo dnf upgrade -yThen turn on automatic security updates so patches don't wait for you: unattended-upgrades on Ubuntu and Debian, dnf-automatic (with apply_updates = yes) on AlmaLinux and Rocky Linux.
2. Lock down SSH
SSH is the front door, and bots try it constantly. The essentials:
- Create a sudo userand stop working as root:
adduser deploy, then add it to thesudogroup (Ubuntu/Debian) orwheelgroup (AlmaLinux/Rocky). - Use a modern key.On your computer run
ssh-keygen -t ed25519, thenssh-copy-id deploy@your-server-ip. - Turn off passwords and root login.Put
PasswordAuthentication no,KbdInteractiveAuthentication noandPermitRootLogin noin a drop-in file such as/etc/ssh/sshd_config.d/00-hardening.conf. - Check before you reload. Run
sudo sshd -tand `sudo sshd -Tgrep -i passwordauthentication`, test a new login in a second terminal, and only then close your old session.
Changing the SSH port away from 22 reduces log noise but is not real protection; if you do it, open the new port in the firewall first, and on AlmaLinux or Rocky also label it for SELinux. The full walk-through is in the SSH security hardening checklist.
3. Firewall and brute-force protection
Default-deny inbound traffic and open only what you serve:
# Ubuntu / Debian (ufw)
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
# AlmaLinux / Rocky Linux (firewalld)
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service={ssh,http,https}
sudo firewall-cmd --reloadNever open database ports such as 3306 (MySQL) or 5432 (PostgreSQL) to the internet. Bind the database to 127.0.0.1 and reach it through an SSH tunnel.
Add fail2ban to ban addresses that keep failing logins. In /etc/fail2ban/jail.local, enable the [sshd] jail with backend = systemd, a maxretry of 3 to 5 and a bantime such as 1h, and add your own static IP to ignoreip. If you install a control panel that ships its own firewall (CSF, for example), use that one and don't run two firewalls side by side. See also modern firewall management with nftables.
4. Protect your websites and applications
- HTTPS everywhere. Get free certificates from Let's Encrypt with Certbot (
sudo certbot --nginxor--apache). Certbot installs a timer that renews automatically; check it withsudo certbot renew --dry-run. - Keep applications patched. Outdated WordPress plugins, themes and frameworks cause far more break-ins than the operating system does.
- Consider a web application firewall. ModSecurity with the OWASP Core Rule Set, or a proxy such as Cloudflare in front of the server, blocks common attacks like SQL injection. Test in detection-only mode first, because the rules can block legitimate requests. See understanding web application firewalls.
- Add security headers such as HSTS and a content security policy; see security headers explained.
- Use mandatory access control that ships with your OS. Ubuntu and Debian use AppArmor and AlmaLinux and Rocky use SELinux, both enabled by default. Leave them on; fix a denial with a proper rule instead of disabling them.
5. Monitor the server and read the logs
You can't fix what you don't see. Start simple:
htop # live CPU, memory and processes
df -h # disk space per filesystem
free -h # memory and swap
sudo journalctl -p err -b # errors since the last boot
sudo journalctl -u ssh --since today # SSH logins (the unit is sshd on AlmaLinux/Rocky)Web server logs normally live in /var/log/nginx/ or /var/log/apache2/ (/var/log/httpd/ on AlmaLinux and Rocky). Make sure logrotate is rotating them; it is installed and configured by default on all these distributions.
For alerts, an external uptime check plus a metrics stack is enough for most businesses. Production observability with Prometheus, Grafana and Loki shows a complete setup.
6. Tune for speed: measure first
Change one thing at a time, and measure before and after.
| Area | What helps | Watch out for |
|---|---|---|
| Caching | A page cache for your CMS, Redis or Memcached for objects and sessions, browser caching headers | Cache only what is safe to share between visitors |
| Database | Set innodb_buffer_pool_size to roughly 50–70% of RAM on a server that mainly runs MySQL or MariaDB; add indexes for slow queries | The old query_cache_size setting was removed in MySQL 8; don't copy old tuning guides |
| PHP | Keep OPcache on, and size PHP-FPM pm.max_children to your available memory | Too many workers causes swapping and slows everything down |
| Web server | nginx worker_processes auto;, gzip or Brotli compression, HTTP/2 | Apache's MaxClients is now MaxRequestWorkers |
| Node.js | Run under PM2 or systemd, one process per CPU core with cluster mode | Don't run production apps from a terminal session |
Remove what you don't use: systemctl list-units --type=service --state=running shows every running service, and sudo systemctl disable --now name stops one.
7. Backups you can actually restore
A backup only counts if it is somewhere else and you have restored it at least once.
- Follow 3-2-1: three copies, on two kinds of storage, one off the server.
- Automate it. A nightly
mysqldumporpg_dumpplusrsyncorresticto remote storage, run from cron or a systemd timer. - Test restores on a spare server or a local virtual machine every few months.
- Know what your provider keeps. Check which snapshots your VPS plan lists on the plan page, and keep your own off-server copy anyway.
8. Network, DNS and DDoS
- Put a CDN such as Cloudflare in front of busy or media-heavy sites; it cuts latency for distant visitors and absorbs a lot of junk traffic. See Cloudflare setup for Indian websites.
- Rate-limit logins and APIs at the web server (for example nginx
limit_req). - For attacks against a single service, mitigating DDoS attacks with CSF covers the server-side options.
- DNSSEC is set up with your DNS provider and registrar. For a domain registered with Domain India, ask support.
9. Your regular maintenance routine
ss -tulpn), and application and plugin updates.10. Running this on a Domain India VPS
Domain India VPS plans use KVM virtualization with full root access and NVMe storage, and they are self-managed: every step in this guide is yours to carry out. At checkout you can choose no control panel, CyberPanel, Webuzo or DirectAdmin; cPanel isn't offered on a VPS. The live VPS page lists the servers as located in Germany, so a CDN is worth considering if most of your visitors are in India. On 19 September 2026, Domain India list prices started at ₹552 a month for VPS Starter, excluding 18% GST.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
If you don't want to manage a server, shared hosting keeps the server security and updates on our side, and the App Platform runs Node.js apps or any Dockerfile without a server to maintain.
What is the first thing to do on a new VPS?
Update the operating system, create a sudo user, add an SSH key, turn off root and password login over SSH, and enable a firewall that allows only the ports you use.
Should I disable SELinux or AppArmor if something doesn't work?
No. Find the denial in the logs and add the correct rule or label instead. These systems contain the damage if an application is compromised.
Can I use query_cache_size to speed up MySQL?
Not on MySQL 8 or later, where the query cache was removed. Size the InnoDB buffer pool to your RAM and add indexes for slow queries instead.
Does Domain India manage security on my VPS?
No. Domain India VPS plans are self-managed. You are responsible for updates, firewall rules, backups and the software you install.
Can I apply these settings on shared hosting?
No. On Domain India shared hosting the server configuration is managed for you and can't be changed by customers. Use these steps on a VPS or dedicated server.
Ready to run your own server? Compare plans on VPS hosting, follow the VPS setup and activation guide, or open a support ticket if you have a question first.
KVM virtualization, full root access and NVMe storage, with your choice of Linux and an optional control panel.
See VPS plans