Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Security Ubuntu

Security Ubuntu

Scheduled Pinned Locked Moved Solved Support
security
9 Posts 4 Posters 1.6k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • O Offline
    O Offline
    ode59
    wrote on last edited by girish
    #1

    Hello,

    I'm thinking of subscribing to your solution. I'd like some clarification about security. I already have vps with contabo. it seems to me that your service is already compatible.

    after the creation of the installation of a vps, there is necessarily a root account to create. which in time is not a good practice.

    • are any unbuntu security measures taken after cloudron installation?
    • change root,
    • port blocking,
    • modify ssh port,
    • setting up a failtoban?
    • system or packet updates?

    the goal for me is to free myself from system administration.
    thanks

    jdaviescoatesJ 1 Reply Last reply
    1
    • BrutalBirdieB Offline
      BrutalBirdieB Offline
      BrutalBirdie
      Partner
      wrote on last edited by
      #2

      Just to make sure, did you see this?
      https://docs.cloudron.io/security/

      Like my work? Consider donating a drink. Cheers!

      1 Reply Last reply
      0
      • O Offline
        O Offline
        ode59
        wrote on last edited by ode59
        #3

        yes, but reading is long and sometimes a bit technical for me. that's why i'd like to be reassured.
        so following this drive, we don't change the root, but you recommend changing the ssh port and not using SSH key authentication?
        Do you have a tutorial on this subject? I didn't see it in the documentation. Unless I skipped a few lines.
        Thanks for your reactivity

        1 Reply Last reply
        0
        • BrutalBirdieB Offline
          BrutalBirdieB Offline
          BrutalBirdie
          Partner
          wrote on last edited by
          #4

          @ode59

          port blocking

          Yes Cloudron does come with an integrated firewall which manages it self.

          modify ssh port

          This is useless and only deters the most basic script kiddies.
          Every port scanner will still find the open ssh port.

          fail2ban

          https://docs.cloudron.io/security/#fail2ban

          system or packet updates

          https://docs.cloudron.io/security/#updates

          the goal for me is to free myself from system administration

          When self hosting you will never be fully "free" of system administration.
          But Cloudron does take a lot of your shoulders.

          Setting up ssh key based authentication and disabling root is explained one google search away for example:
          https://www.cyberciti.biz/faq/how-to-disable-ssh-password-login-on-linux/

          Like my work? Consider donating a drink. Cheers!

          1 Reply Last reply
          1
          • girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by
            #5

            I recommend following the two steps in the post installation - https://docs.cloudron.io/installation/#firewall-setup . i.e if you have a Cloud firewall open/close ports there and also secure ssh access with ssh keys and disable password login.

            1 Reply Last reply
            2
            • O Offline
              O Offline
              ode59
              wrote on last edited by ode59
              #6

              Thank you very much.

              When self hosting you will never be fully "free" of system administration.

              what are the "remaining" tasks you are talking about?

              girishG 1 Reply Last reply
              0
              • O ode59

                Thank you very much.

                When self hosting you will never be fully "free" of system administration.

                what are the "remaining" tasks you are talking about?

                girishG Offline
                girishG Offline
                girish
                Staff
                wrote on last edited by
                #7

                @ode59 IT stuff like configuring apps, figuring out how apps work, figuring out which apps you need, maybe setting up interconnections between apps. in any case, instead of talking in abstract, it's best you try to actually use it and see how you like it 🙂

                1 Reply Last reply
                1
                • girishG girish marked this topic as a question on
                • girishG girish has marked this topic as solved on
                • O ode59

                  Hello,

                  I'm thinking of subscribing to your solution. I'd like some clarification about security. I already have vps with contabo. it seems to me that your service is already compatible.

                  after the creation of the installation of a vps, there is necessarily a root account to create. which in time is not a good practice.

                  • are any unbuntu security measures taken after cloudron installation?
                  • change root,
                  • port blocking,
                  • modify ssh port,
                  • setting up a failtoban?
                  • system or packet updates?

                  the goal for me is to free myself from system administration.
                  thanks

                  jdaviescoatesJ Offline
                  jdaviescoatesJ Offline
                  jdaviescoates
                  wrote on last edited by
                  #8

                  @ode59 said in Security Ubuntu:

                  the goal for me is to free myself from system administration.

                  In short, you're in the right place.

                  One very rarely has to SSH into one's server to do anything with Cloudron as nearly everything is handled by Cloudron.

                  I use Cloudron with Gandi & Hetzner

                  1 Reply Last reply
                  0
                  • O Offline
                    O Offline
                    ode59
                    wrote on last edited by
                    #9

                    OK, I'll try.
                    Thanks for your suggestions.

                    1 Reply Last reply
                    0
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Don't have an account? Register

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • Bookmarks
                    • Search