A new VPS has a public IP from the very first minute, and a public IP gets automated login attempts within hours. None of this is an attack aimed at you — it's continuous scanning that tries common passwords on every address that responds. This is the minimum to avoid being an easy target.
The installed image was built on a certain date; everything fixed after that is still open on your machine.
apt update && apt upgrade -y
On AlmaLinux, Rocky Linux and CentOS:
dnf upgrade -y
passwd
Use a long, unique password generated by a password manager. The password from the credentials email passed through an inbox and shouldn't stay valid.
Working as root all the time turns any typo into damage. Create a regular user and give it admin access on demand:
adduser myname
usermod -aG sudo myname
On AlmaLinux and Rocky Linux, the group is wheel instead of sudo.
A key can't be guessed, and it takes your machine out of reach of password scans. The step by step is in How to access your Linux VPS via SSH.
With the key working — and only after confirming it in a second terminal window — disable password login in /etc/ssh/sshd_config:
PasswordAuthentication no
PermitRootLogin prohibit-password
Reload the service:
systemctl restart sshd
Every open port is more attack surface. Open only what your application uses.
On Ubuntu and Debian, with ufw:
ufw allow OpenSSH
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
On AlmaLinux and Rocky Linux, with firewalld:
firewall-cmd --permanent --add-service=ssh
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
It reads the authentication logs and blocks IPs that get the password wrong several times in a row.
apt install fail2ban -y
systemctl enable --now fail2ban
The default configuration already covers SSH.
Administrator password on first login.Administrator — it's the user every scan tries first.This protection handles the traffic that reaches the machine. The password, the firewall and the programs running inside it remain the responsibility of whoever manages it — that's the split on a VPS with root access.