Blog topic

VPS security guides

Hardening, lockout recovery and safe disposal.

Security for servers you rent by the hour or the month, ordered so you never lock yourself out. The VPS security checklist takes a new Ubuntu 24.04 server from first login to key-only SSH, a firewall and automatic security updates in about 15 minutes, and most tutorials on this blog link back to it. When a server's job is done, the delete VPS checklist covers backups, DNS records, keys and the IP address the server leaves behind. To report a vulnerability in HourlyVPS systems, see security and vulnerability disclosure; what you may run on a server is set by the acceptable use policy.

  • 3 posts
  • Last review

Posts in Security

  • VPS Backup with Restic: Encrypted Off-Site Backups to S3 (2026)

    Set up an encrypted, off-site VPS backup with restic on Ubuntu 24.04: S3-compatible storage, a nightly systemd timer, sensible retention, failure alerts and a restore you have rehearsed.

    • A VPS backup only counts if it lives off the server: at HourlyVPS a deleted server's disk cannot be recovered…
    • Install restic 0.19.1 from the checksum- and signature-verified official binary; Ubuntu 24.04's 0.16.4 package lacks --stdin-from-command…
    • Keep the repository password and bucket key in a password manager as well as in root-only files…

    19 min readLast reviewed