VPS Security Hardening — Automated Server Lockdown
- problem
- A personal cloud VPS running an AI gateway and LLM stack sat on the public internet with a default posture: public SSH, exposed services, no firewall policy. A single misconfigured daemon away from a compromise.
- approach
- Rebuilt the host around deny-by-default: UFW with every allow rule scoped exclusively to the mesh-VPN interface, public SSH listeners disabled, SSH hardened (MaxAuthTries, idle timeouts, AllowUsers restrictions), and fail2ban progressive-ban policies tuned. Daily config backups automated via cron with GitHub push for change tracking and disaster recovery.
- result
- 0 public inbound firewall rules — every allow rule scoped to the private mesh, public SSH disabled. The hardened state is live and verifiable in the public report: before/after port scans, full service inventory, and rollback procedures.
constraint: locking SSH behind the mesh meant giving up the convenience of reaching the box from any network — the fix was accepting that friction as the design, not engineering around it.
stack: UFW · fail2ban · Tailscale · Ubuntu 24.04
open github.com/BenkoMatt/VPS-Security-Hardening-Report