How do I set up a Linux server for the first time?
Initial installation and updates
Choose a distribution — Ubuntu, Debian, CentOS, or Rocky Linux are common for servers. Most cloud providers offer these as pre-built images. During installation, set a strong root password and create at least one regular user account.
After the first boot, log in and immediately update all packages. On Debian/Ubuntu run sudo apt update && sudo apt upgrade; on RHEL-based systems run sudo dnf update. Reboot if the kernel was updated.
Secure access and users
Create a non-root user with sudo privileges if the installer didn't already. Add your SSH public key to ~/.ssh/authorized_keys for that user. Then edit /etc/ssh/sshd_config to set PermitRootLogin no and PasswordAuthentication no, and restart SSH.
Install a firewall like UFW (Ubuntu) or firewalld (RHEL) and allow only the ports you need — typically SSH (22), HTTP (80), and HTTPS (443). Enable the firewall and test that you can still connect before closing your session.
- Update all packages
- Create a sudo user
- Add SSH keys
- Disable root SSH login and password auth
- Enable a firewall with minimal open ports
- Set up automatic security updates if available
Ongoing maintenance
Consider enabling automatic security updates (unattended-upgrades on Debian/Ubuntu, dnf-automatic on RHEL). Set the server's timezone and hostname, and configure log rotation if you expect high traffic.
For production, install only the services you need, keep them patched, and monitor logs. A minimal setup reduces the attack surface and makes troubleshooting easier.
Common mistakes
- Leaving root login and password authentication enabled over SSH, which invites brute-force attacks.
- Skipping updates right after installation, leaving known vulnerabilities open.
- Opening all firewall ports 'just in case' instead of allowing only what's needed.
