Linux VPS Tutorial for Beginners: SSH, Security & First Deploy
Your first Linux VPS can feel intimidating. This tutorial walks through SSH, updates, a sudo user, firewall basics, and a safe first deploy on paid infrastructure.
By Vision Host Editorial Team - Infrastructure & Hosting Specialists
What you need before starting
You need a paid VPS IP, root or initial password/key from the provider panel, and a local terminal (Windows Terminal, macOS Terminal, or Linux). Vision Host VPS on /vps-hosting starts from ₹879/mo - no free VPS claims.
Pick Ubuntu LTS or Debian for beginners; community answers are abundant. Set your laptop timezone awareness to IST for cron later, even if the server uses UTC.
If you only wanted a Discord bot online, consider /discord-bot-hosting from ₹24/mo instead - this tutorial assumes you truly want Linux practice or root workloads.
First SSH login
From your PC: ssh root@YOUR_IP and accept the host key fingerprint carefully. If the provider gave a temporary password, change it immediately after login.
Prefer SSH keys. Generate a key locally, add the public key to the server, and disable password authentication only after key login works - do not lock yourself out.
If connection times out, check the provider firewall/security group and your local network. Some school/office networks block outbound 22.
- Login with SSH
- Update packages (apt update && apt upgrade)
- Create a non-root sudo user
- Add your SSH key to that user
- Configure ufw/firewalld basics
- Enable automatic security updates thoughtfully
Create a sudo user and reduce root risk
Running daily tasks as root increases blast radius. Create a user, add to sudo group, test sudo, then use that account for deploys.
Keep root available via console/VNC in the provider panel in case you firewall yourself out. Know where the emergency console lives on Vision Host’s billing panel before you need it.
Use unique passwords stored in a password manager. Reused passwords are how random VPS get mined overnight.
Firewall essentials
Allow SSH (22 or your custom port), then HTTP/HTTPS if you host web services, then application ports like 25565 for Minecraft only when needed. Default deny incoming otherwise.
Order of operations matters: allow SSH before enabling the firewall. Thousands of beginners learn this the hard way.
For databases, bind to localhost or private interfaces - never expose Mongo/MySQL to 0.0.0.0 without a plan.
| Port | Service | Expose publicly? |
|---|---|---|
| 22 | SSH | Yes (key-only preferred) |
| 80/443 | Web/TLS | If hosting sites |
| 25565 | Minecraft | If running MC |
| 3306 | MySQL | Usually no |
| 27017 | MongoDB | Usually no |
Updates and unattended upgrades
Apply security updates regularly. On Ubuntu, unattended-upgrades can patch security issues automatically; still reboot when kernels require it during a maintenance window.
Hold freezes carefully if an app pins ancient libraries - but do not ignore CVEs forever.
Snapshot before major upgrades when your VPS provider offers snapshots - Vision Host paid plans support operational hygiene like this.
Deploy something small to learn
Install Node or Python, run a hello-world service under systemd, and confirm it survives reboot. That teaches process management better than any slideshow.
For Discord bots, create a systemd unit with Restart=always and environment files with locked-down permissions.
For Minecraft, either install a panel (see Pterodactyl guide) or run a simple Paper test with screen/tmux - then graduate to proper process supervision.
Backups and monitoring basics
Copy critical directories off the VPS weekly. A second Vision Host storage location or local encrypted drive works. Test a restore once.
Monitor disk with df -h and memory with free -h. Full disks silently break databases and SSL renewals.
Optional: uptime monitors that ping SSH or HTTPS and alert in Discord when the VPS is unreachable.
Next steps and safer alternatives
When comfortable, add nginx, containers, or Pterodactyl. When uncomfortable, offload to managed /minecraft-hosting or /discord-bot-hosting and keep the VPS for learning labs only.
Never practice security on a free flaky VPS that may vanish - use paid /vps-hosting so your study environment persists.
You now have the skeleton of professional VPS ops: access, updates, least privilege, firewall, deploy, backup.
Quick answers
Featured-snippet style FAQs for this topic.
