Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm in no way a person who run some cluster on bare metal servers, but managing them are not any different than cloud compute instance. Only extra thing you need is to have some monitoring for SMART status of your drive.

> I am much more comfortable working on a compiler than setting up a server in a way that it doesn't get pwned

99% of the time all you need is to have firewall up, password login off and unattended upgrades enabled. It's will literally never get pwned then.



I add fail2ban as good measure too.

I don't know about literally, but it helps.


It's can certainly be useful if you use anything with password auth or just want to avoid logs full of bots, but otherwise just change default SSH port.


If you only allow incomming traffic to sshd, and require ssh-key login (no password login), fail2ban will likely only add complexity, not security.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: