Delivery kit

Annex — Self-hosted: VPS hardening

Last changed 2026-08-05 · all documents · security & deployment

Applies when something runs on a virtual machine I administer. This annex adds to baseline-runbook.md and annex-tier2.md.

First question every time: does this need a VPS at all? A managed platform removes most of this page's work and most of its risk. I only take on a VPS when the client's constraints genuinely require it, and I say who is responsible for patching it after handover before it is built. An unowned VPS is a liability with a monthly bill.

The host is in an EU/EEA region and runs a current LTS distribution.

SSH keys only

Firewall

Automatic patching

fail2ban

The rest of the baseline still applies

Disk encryption where the provider offers it, secrets injected at runtime rather than sitting in files on the box, logs shipped somewhere they survive the machine dying, backups tested by restoring onto a fresh instance, and the whole host listed in the access register and the data-flow diagram. If the box holds client data, it goes in the Art. 30 register too.