How to improve your SSH security
Quick answer
Use key-based authentication instead of passwords, disable root login over SSH, keep an eye on failed login attempts with a tool like fail2ban, and keep your server's software up to date.
SSH is the main way you'll manage a Linux server, which also makes it the main target for automated attacks. A handful of standard hardening steps closes off most of that risk.
Use key-based authentication
Add an SSH key pair
Generate a key pair on your own machine and copy the public key to the server's ~/.ssh/authorized_keys file. For Flexible VPS, add your key under Flexible VPS → Settings in Portal (manually, or imported from GitHub/GitLab) before creating the server, or paste it in during creation.
Disable password authentication
Once your key works, set PasswordAuthentication no in /etc/ssh/sshd_config and restart the SSH service. This removes password guessing as an attack path entirely.
Disable direct root login
Set PermitRootLogin no in /etc/ssh/sshd_config and use a regular user with sudo instead. This means an attacker who guesses or steals credentials for one account still can't log in as root directly, and every privileged action is tied to a named user in the logs.
Rate-limit and block repeated login attempts
Install a tool such as fail2ban to watch your authentication logs and temporarily block IP addresses after repeated failed login attempts. This cuts down the noise from automated scanning bots and slows down brute-force attempts significantly.
Keep software up to date
Apply operating system and OpenSSH security updates promptly. Most SSH compromises exploit known, already-patched vulnerabilities rather than anything novel, so staying current closes that door.
Other steps worth considering
- Change the default SSH port to cut down on automated scanning noise. See How to change the SSH port.
- Restrict SSH access to specific IP addresses or ranges with a firewall, if your team connects from known locations.
- Limit which users are allowed to connect over SSH with the
AllowUsersorAllowGroupsdirective insshd_config.