A managed KVM VPS is a virtual machine with its own kernel and isolated CPU, memory, and disk, with the security setup done before the application goes live. If you still receive root access, validate the box and close SSH. These are the first commands, on Ubuntu 22.04 or 24.04.
How this compares with shared hosting is in managed VPS or shared hosting. The plan where engineering does this setup is the KVM VPS.
1. Confirm the hypervisor is KVM
systemd-detect-virt
free -h
nproc
lsblk
systemd-detect-virt should print kvm. free -h and nproc show the plan's RAM and vCPUs. lsblk lists the disk. If the command prints openvz or lxc, the server does not have its own kernel and several steps below do not apply.
2. Update and create the operator user
Log in as root only for this first session.
apt update && apt upgrade -y
adduser deploy
usermod -aG sudo deploy
On your laptop, create a key if you do not have one and copy it to the server:
ssh-keygen -t ed25519 -C "deploy@company"
ssh-copy-id deploy@VPS_IP
Open a second terminal and confirm that ssh deploy@VPS_IP logs in without a password. Only then continue. Closing root before that test locks the server.
3. Disable root login and passwords
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo sshd -t && sudo systemctl reload ssh
sshd -t checks the file. If it reports an error, do not reload the service. Keep the current session open and test the key login from another terminal.
4. Firewall, fail2ban, and automatic updates
sudo apt install -y ufw fail2ban unattended-upgrades
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw enable
sudo ufw status
Ubuntu does not enable the SSH jail by default. Create /etc/fail2ban/jail.local:
[sshd]
enabled = true
maxretry = 5
bantime = 1h
sudo systemctl enable --now fail2ban
printf 'APT::Periodic::Update-Package-Lists "1";\nAPT::Periodic::Unattended-Upgrade "1";\n' | sudo tee /etc/apt/apt.conf.d/20auto-upgrades
sudo systemctl enable --now unattended-upgrades
sudo timedatectl set-timezone UTC
ufw status must show the OpenSSH rule as ALLOW. Without it, the next login will not connect.
5. What to check before the application
df -h
timedatectl
sudo fail2ban-client status sshd
Free disk, the right timezone, and the sshd jail active. The application comes after that: a service user without sudo, the app port behind Nginx, and backups off this machine. CPU and disk monitoring is in Grafana on a VPS.
Conclusion
These commands leave the KVM VPS with one user, a key, a firewall, and security updates. That is the minimum before any site is published. On a managed VPS this first day is already done, and the team keeps root for the application.