Basic server setup (Ubuntu)
Disclaimer: This short guide is basically just a reminder to myself, where most of the content is based on Digital Ocean's Initial Server Setup with Ubuntu 16.04 and my own memory. There are some important steps that aren't included in this guide. If you're new to Linux or Ubuntu, I suggest that you read Digital Ocean's guide instead.
All commands in this guide (unless otherwise stated) assume you are currently logged in as root.
Add a user
We don't want to use the root user when logging in to our server, so we need to create a new user.
If you're only using keys to log in to your server (which you should), you can choose to not create a password for the new user using the
--disabled-passwordoption. Please note that you'll be unable to usesudowith this user unless you also perform the steps in this post.
adduser <user> [--disabled-password]
Root privileges
Our newly created user will typically need root privileges:
usermod -aG sudo <user>
Now, if you want this user to be able to use sudo without the need for a password, here's how to accomplish this.
Public Key Authentication
At this point we're ready to copy the public keys to the newly created user's .ssh folder. I won't cover all the details of this process in this guide. Please refer to the previously mentioned Digital Ocean guide if you're uncertain of how to do this.
We will need to set the correct permissions:
Note: These commands assume you are logged in as your newly created user.
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
Also make sure that these files are owned by the user we just created.
Disable password authentication
On new Digital Ocean droplets, this step is usually already done when creating the droplet. Just to make sure, we'll check to see if the file /etc/ssh/sshd_config contains the following lines and that none of them are commented out:
PasswordAuthentication no
PubkeyAuthentication yes
ChallengeResponseAuthentication no
If you did any changes, reload the SSH daemon:
systemctl reload sshd
Note: Try connecting to your server in a separate tab/window before disconnecting.
Firewall
We need to make sure that our server doesn't expose unnecessary ports and protocols, so lets configure UFW in the most basic way possible:
ufw allow OpenSSH
ufw enable
Note: At this point you should once more verify that you're able to log in to your server.
This concludes this short guide on how to perform the initial steps when creating a new Ubuntu (16.04) server.
Next steps
Here are a few things you can do:
- Reply to this post by email – I’d love to hear from you.
- Browse all writing
- Subscribe via RSS or email to stay in the loop.
- Reach out on Mastodon – I’m always happy to chat.
2026
September
-
Note
As quite evident by looking at my brand new reading page, I haven't read very much this year. Going forward I will do my very best to finish the books I'm currently reading and find some new exciting books to read. Currently only finished three, the goal is 10!
-
Note
I just ordered a Fairphone 6+, Fairbuds and Fairbuds XL.
I have an iPhone 17 as my daily driver, but I couldn't help but order this phone and headsets once I became aware it was a thing.
My plan is to switch to all of these things, replacing my iPhone 17, AirPods Pro 3 and Bose QuietComfort Ultra. These will either be sold or given to someone who needs them.
The initiative is great and their values even better. We need companies trying to counter the enormous pressure laid upon all of us to keep buying stuff all the time.
I will post a thorough review of these items once I've used them for a while.
-
Tømmerneset rock carvings
2025
April
-
Note
I will be posting changes to my website simply as notes tagged with
changelog. This is the very first changelog of this site, and it summarizes the most important changes I've done since I started wiping the dust of this site in April this year.- I've added a Buttondown newsletter integration. Whenever I publish a new post on my blog, an email will be sent to my subscribers.
- I've added a «Reply by email» button to all content. Do not hestitate to contact me if you have comments or feedback. Getting feedback is a big part of why I blog in the first place — I enjoy hearing from readers and being part of a thoughtful exchange now and then.
- I've added a Search feature using Pagefind. It's not yet fully configured or customized, but it's working.
- Added links to previous and next post, note and link.
- Added a 404 page.
- Reduced the size of uncompressed resources being loaded on the front page to 66 kB. Submitted a PR to be added to the 512kb.club website.
-
Our dog: Kento
-
Note
This is the very first note on my new website. It's a GREAT note.
It doesn't say much, but still – it marks the beginning of a new note-hosting era for this website.
-
Back to basics – again..