Linux Permissions and Server Security
Server security starts with operating-system basics: users, groups, permissions, updates, limiting services and controlling what is exposed to the network. This is not a list of magic settings, but a set of mechanisms for reducing risk deliberately.
Related topics: SSH and Remote Administration, Debian Desktop and Server, Docker and systemd, cron and Schedulers.
1. Users and groups
id
whoami
groups
sudo adduser app
sudo groupadd developers
sudo usermod -aG developers user
2. Permissions
ls -l
Example:
-rw-r----- 1 app developers config.yml
Meaning:
owner: rw-
group: r--
others: ---
3. chmod
Symbolic:
chmod u+x script.sh
chmod g-w file
chmod o-r file
Numeric:
r=4
w=2
x=1
Examples:
chmod 640 config.yml
chmod 755 script.sh
4. chown
sudo chown app:app file
sudo chown -R app:app /srv/myapp
5. sudo
Do not work permanently as root.
sudo command
sudo visudo
6. SSH keys
ssh-keygen -t ed25519
ssh-copy-id user@server
7. sshd
Configuration:
/etc/ssh/sshd_config
After changes:
sudo sshd -t
sudo systemctl reload ssh
Never close the active session before confirming that a new login works.
8. Disable password authentication
After verifying key login:
PasswordAuthentication no
9. Root login
Common setting:
PermitRootLogin prohibit-password
or disable it completely.
10. Firewall
On Debian you can use nftables or UFW.
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose
11. Open the minimum
Typical web VPS:
22/tcp SSH
80/tcp HTTP
443/tcp HTTPS
PostgreSQL does not need to be public if only the local backend uses it.
12. Updates
sudo apt update
sudo apt upgrade
Pay attention to services that require restart.
13. Services
systemctl --type=service --state=running
sudo systemctl disable --now SERVICE
Disable unnecessary services.
14. Separate service user
[Service]
User=myapp
Group=myapp
ExecStart=/srv/myapp/myapp
15. Secrets
Example file:
/etc/myapp/myapp.env
Permissions:
sudo chown root:myapp /etc/myapp/myapp.env
sudo chmod 640 /etc/myapp/myapp.env
16. fail2ban
It can block repeated login attempts, but it does not replace good SSH keys and configuration.
17. SSH logs
journalctl -u ssh
18. Port audit
ss -lntup
Ask: why is this port open, which process uses it and does it need to be public?
19. Backup
Operational security without backups is incomplete.
Backups should be automated, tested, off-server and rotated/versioned.
20. Least privilege
Every component should have only the permissions it needs: users, files, databases, APIs, containers and CI/CD.
21. New VPS checklist
- create a normal user,
- add an SSH key,
- verify login,
- update the system,
- configure firewall,
- restrict SSH,
- run applications as separate users,
- configure backups,
- inspect open ports,
- configure monitoring and logs.
22. What you should know
You should understand chmod/chown, users/groups, SSH key authentication, firewalling, systemd service users, open-port inspection and basic VPS hardening.
Official references
- GNU Coreutils - file permissions: https://www.gnu.org/software/coreutils/manual/html_node/File-permissions.html
- OpenSSH sshd_config: https://man.openbsd.org/sshd_config
- Debian Security: https://www.debian.org/security/