{"repo":"alexandreravelli/vps-ubuntu-24-04-hardening-dokploy","free":true,"listed":false,"github":"https://github.com/alexandreravelli/vps-ubuntu-24-04-hardening-dokploy","clone":"git clone https://github.com/alexandreravelli/vps-ubuntu-24-04-hardening-dokploy.git","description":"Interactive Bash scripts that apply a pragmatic hardening baseline to a fresh Ubuntu 24.04 LTS VPS: SSH, UFW, Fail2Ban, AppArmor, sysctl/kernel settings, Docker firewall, and optional Dokploy install.","language":"Shell","stars":73,"topics":["bash","docker","dokploy","hardening","security","self-hosted","traefik","ubuntu","vps","apparmor"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"VPS Hardening Script A pragmatic hardening baseline for fresh Ubuntu 24.04 VPS servers. Hardened SSH, firewall, sysctl, ASLR, Fail2Ban, auditd, auto-updates. Docker + Dokploy optional. Quick Start · Requirements · What It Does · After Installation · Security · FAQ --- 🚀 Quick Start Step 1 — Harden the server Connect to your VPS and run: The script answers all your questions first, then applies hardening automatically. If your SSH session drops during hardening, the script continues in the background — reconnect with screen -r hardening . Step 2 — Install Docker + Dokploy (optional) Reconnect on your new SSH port, then: Not root? No worries — both scripts detect this and auto-escalate with sudo . --- 📝 Requirements - Fresh Ubuntu 24.04 LTS VPS - User with sudo privileges - SSH public key ready ( ssh-ed25519 or ssh-rsa ) — or let the script generate one External firewall (OVH, Hetzner, AWS, etc.): If your VPS provider has a network-level firewall, open these ports in their control panel before running the relevant step: Port Protocol Purpose When to close ------ ---------- --------- --------------- 22 TCP SSH (default, script will move it) After confirming new SSH port works 80 TCP HTTP / HTTPS certificate validation Keep open 443 TCP HTTPS Keep open 3000 TCP Dokploy initial setup (temporary) After configuring your domain + HTTPS custom TCP New SSH port (shown before setup starts and saved at the end) Keep open The exact SSH port is displayed before setup starts and saved in ","default_branch":null,"files":null,"tree":[],"storefront":"/r/alexandreravelli","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/alexandreravelli/vps-ubuntu-24-04-hardening-dokploy/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}