Skip to content

What Does Initial Linux Server Configuration Include?

The basic configuration of Linux includes inventory, patch, SSH, firewall, user limit, time, backup, log and monitoring; in secure order and recovery path.

Author Bipida Editorial Team Published
Share this article

The server's initial configuration is a set of security and operational decisions, not a list of copying commands. A server that only has its SSH on another port but has no recoverable backup, regular patch, correct timing, and alert is not ready for production.

Quick answer:Take inventory from the current status, verify the emergency console, patch the system and create a separate management account with SSH key. Step-by-step harden the firewall and SSH; then set and test the time, DNS, log, backup, monitoring, and maintenance policy.

Stage Zero: Owner and target of the server

Record the server role, production/staging environment, domain, sensitive data, RPO/RTO and respondent. Specify which services to run and what not to install. Public server that has a shared web, database, test tool and account simultaneously increases the attack and blast radius.

Inventory reading

cat /etc/os-release
uname -r
ip -br addr
ss -lntup
free -h
df -h
df -i
systemctl --failed

These commands do not change the status. Record the system version, interfaces, listener, memory, disk, inode, and failed service. Anonymously identify the public IP, internal hostname, and username before sharing. Each listener must have a specific owner and reason.

Emergency access before the hardening.

Open the console or recovery mode of the provider, not just assume that it exists. The credential and MFA of the provider account must be allowed in a secure and accessible team location. If the firewall or SSH goes wrong, this path is the only way back.

Patch and cycle updates

Get packages from a valid repository and apply security updates. Changing the kernel or critical library may require reboot or restart; maintenance window and service review are required afterwards. Automatic update without reboot and smoke test policies may change the service at an inappropriate time; it is also not appropriate to turn off the update completely.

The management user is different.

For each account manager, have a separate sudo and password. The public key is stored on the server; the private key must remain secure on the device and never be sent to the repository or public message. The separate account allows for revoke and audit. Shared root password makes both responsibility ambiguous and rotation difficult.

SSHs are locked in unlocked order.

  1. Add the key and check its permission.
  2. Test the login in the second session.
  3. Test sudo and essential access.
  4. Verify the config with the same daemon tool.
  5. Implement the root/password restriction step by step.
  6. Hold the previous session and console until confirmed.

Changing the port only reduces the scan noise; it does not replace key, allowlist, patch, and rate control. SSH algorithms and options are dependent on the distribution version; do not blindly replace the old template.

Firewall based on real-time

Restrict access to essential services and verify the management rule before activating it. HTTP/HTTPS is public, but the database, Redis, and internal panel should usually be private. Outbound also requires a map for updates, DNS, NTP, email, and APIs. Extreme rule without documentation can interrupt callback or backup.

Cloud and Host Firewalls

The firewall provider and the operating system are two-layered. Their differences make it difficult to troubleshoot; have source of truth and change record. Docker or orchestration tools may also add network rules. Just don't see the firewall interface output; test the actual path from the outside and the inside network.

Time, NTP and timezone.

The wrong time will spoil the TLS, token, cron, log and match incident.timedatectl statusCheck. The timezone is for human display; the correct clock and the applicable timestamp are more important. Changing the clock hand to pass the signature error hides the problem and time data is confusing.

Hostname, DNS and Reverse DNS

Choose a meaningful hostname but without sensitive information. A and AAAA records should only refer to actually active routes. IPv6 makes timeout incomplete for some users. Reverse DNS is particularly important for email and is usually set in the provider panel; do not confuse it with forward DNS.

At least the service and the package source.

Deactivate or delete the unused service after the inventory is disabled. The third-party repository enters a new trust level and must have the owner, signature key, and update cycle specified. Installing an unknown bootstrap panel or script can change the firewall, web server, and SSH at the same time; first check the content and rollback path.

The principle of minimum access for processes

The program, web server, and database should not run root for no reason. Separate code ownership, upload files, logs, and secret.777The treatment is not permissioned and allows for unwanted writing.

Secret Management

Do not include database code, API key, and private key in the repository, public image, history shell, or log. The secret file must have limited owner and permission and its rotation is scheduled without downtime. Hiding values in the UI does not neutralize previous disclosure; the disclosed credential must be rotated.

Set the resource limit

A no-limit service can consume all memory or file descriptor; a very low limit also creates a blurred error. Measure actual consumption, concurrency, and failure behavior. Define a coherent source budget for PHP, database, container, and systemd so that the total ceilings do not exceed physical capacity.

Swap and OOM.

The existence or absence of swap is not an absolute decision. Small swaps can give an opportunity, but they can increase the intensity of latency and not enough RAM. Monitor OOM event, memory pressure and working set services.

The log and the journal.

Log authentication, firewall, web server, application and database must have a specific location, retention and owner. Test the rotation before the disk is filled. Do not record the secret, cookie and payload of payment. A shared timestamp and request ID helps track an event from proxy to application.

Independent and encrypted backup.

Compatibly backup the database, user file, and configuration and keep a copy outside the same server/account. Determine retention, encryption, and restore access. Backup without the restore test is a hypothesis. Perform a periodic recovery on a separate environment and compare real-time to RTO.

Basic monitoring

  • TLS service access and validity
  • CPU, load, RAM, swap and OOM
  • Disk, inode and I/O latency
  • Listener and critical processes
  • Error rate and p95 response
  • Recent backup and job results.

Each alert should have severity, responsiveness, and runbook. The alert is after the disk is 100% late; the threshold should give the opportunity to act and also indicate the growth trend.

Audit and recording changes

Who, when and why has changed the configuration? Copy the files but do not enter the secret into Git. Release or ticket must be validated and rollback. Manual changes without registration will cause configuration drift and return error to the next server.

Smoke test delivery

ss -lntup
systemctl --failed
journalctl -p err -b
df -h
free -h

The error message in the journal is not necessarily incident-activated; check the service and timestamp. Test the authorized SSH, HTTP/HTTPS, DNS and closed ports from the outside. Then verify the controlled reboot and auto-start of the services if possible.

Order of delivery of production

  1. Inventory and recovery access
  2. Patch and reboot controlled.
  3. user and SSH key
  4. Firewall and network testing.
  5. Time, DNS and TLS
  6. Runtime and services.
  7. Backup and restore test.
  8. Monitor, alert and documentation

To fully deploy the site on Ubuntu,The Ubuntu server setup guideIt also covers the web layer, runtime, and DNS.

Common Mistakes

  • Lock the password/root before the key test.
  • Firewall without an emergency console.
  • Database or Redis release
  • Running everything with root.
  • License.777
  • Secret in Git and log
  • Backup without restore test
  • No one is responsible.

When do you need special assistance?

If the server is production, store, or has a limited network, the wrong SSH and firewall configuration can block access.Install and configure the Linux serverIt can implement baseline security, backup, monitoring and recovery documentation as per the service.

Common Questions

Is the Hardening script ready enough?

No, you need to check the changes, the distribution version, the program requirements and the rollback.

Is Fail2ban necessary in the first place?

It can be useful, but after the correct log, SSH keys, firewalls and allowlist, it doesn't replace them.

How long will the server be patched?

Based on severity, exposure and maintenance policy, critical updates should not be delayed until a fixed calendar.

Why should we test rebooting?

To test auto-start, mount, network and dependencies before they actually happen.

How to Set Up an Ubuntu Server for a Website
To set up the Ubuntu server securely, prepare access, patch, SSH, firewall, web server, TLS, backup, monitoring and rollback before DNS is transferred.