Ubuntu server setup (VPS)

Ubuntu server setup (for new VPS onboarding)

Installation

Ghostty settings

# Fix 
# root@riguz4c8g:~# clear
# 'xterm-ghostty': unknown terminal type."

infocmp -x xterm-ghostty | ssh root@83.229.121.141 -- tic -x -

Update system

sudo apt update
sudo apt full-upgrade -y
sudo apt autoremove --purge -y
root@riguz4c8g:~# lsb_release -a
No LSB modules are available.
Distributor ID: Ubuntu
Description:    Ubuntu 24.04.5 LTS
Release:        24.04
Codename:       noble

Not recommended to do-release-upgrade (from 24 -> 26)

System settings

Add admin user:

adduser riguz
usermod -aG sudo riguz


hostname

vim /etc/hostname

ssh config

ssh-copy-id -p 50000 ubuntu@12.98.23.12

# vim /etc/ssh/sshd_config
Port 54194
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes

service ssh restart
ssh -p 50000 ubuntu@12.98.23.12

Note: for Ubuntu 24.04+ with systemd socket

# To change the port
sudo vim /lib/systemd/system/ssh.socket
[Socket]
ListenStream=0.0.0.0:54194
ListenStream=[::]:54194

sudo systemctl daemon-reload
sudo systemctl stop ssh.socket
sudo systemctl restart ssh
netstat -anp | grep 54194
(No info could be read for "-p": geteuid()=1000 but you should be root.)
tcp        0      0 0.0.0.0:54194           0.0.0.0:*               LISTEN      -
tcp6       0      0 :::54194                :::*                    LISTEN      -

ufw

sudo ufw enable
sudo ufw allow 80
sudo ufw allow 443
sudo ufw allow 54194
sudo ufw status numbered

V2ray

V2Ray global proxy

Web server

Ngnix

$ sudo apt install nginx
$ sudo systemctl status nginx

Add deploy user (Github actions)

sudo adduser --disabled-password deploy

sudo mkdir -p /home/deploy/.ssh
sudo touch /home/deploy/.ssh/authorized_keys
sudo chmod 700 /home/deploy/.ssh
sudo chmod 600 /home/deploy/.ssh/authorized_keys
sudo chown -R deploy:deploy /home/deploy/.ssh

# generate new key in local pc
ssh-keygen -t ed25519 -C "gh-actions-deploy-$(date +%Y%m%d)" -f ~/.ssh/gh_deploy_new

# save pub key to authorized_keys in server
cat gh_deploy_new.pub
sudo vim /home/deploy/.ssh/authorized_keys

cat gh_deploy_new
# save private key to DEPLOY_KEY

# verify if the key is able to login
ssh -i ~/.ssh/gh_deploy_new -o IdentitiesOnly=yes -p 2222 deploy@83.229.121.141

Certbot

Install via pip[1]

sudo apt install certbot
sudo apt install python3 python3-dev python3-venv libaugeas-dev gcc
sudo python3 -m venv /opt/certbot/
sudo /opt/certbot/bin/pip install --upgrade pip
sudo /opt/certbot/bin/pip install certbot certbot-nginx
sudo ln -s /opt/certbot/bin/certbot /usr/bin/certbot
sudo certbot --nginx
sudo nginx -s reload