Ubuntu Server LTS Setup Guide (20.04 / 24.04)
This guide assumes you’re provisioning a fresh Ubuntu Server LTS instance (20.04 or 24.04) on a VPS or cloud provider.
1. Create a non‑root sudo user
adduser yourUserName
usermod -aG sudo yourUserName
2. Get SSH key access to the new user
If your host doesn’t support injecting public SSH keys at creation time, copy your key from your local machine to the temporary root login:
ssh-copy-id ro**@**********ne.ip.000
Once logged in as root, transfer the SSH keys to the new user:
rsync --archive --chown=yourUserName:yourUserName /root/.ssh /home/yourUserName
Exit and reconnect as the new user:
exit
ssh yo**********@**********ne.ip.000
3. Harden SSH
After confirming you can log in as yourUserName, disable root SSH access:
Edit the SSH daemon config:
sudo nano /etc/ssh/sshd_config
Ensure the line reads: PermitRootLogin no
Restart SSH:
sudo service ssh restart
Important: Keep one active SSH session open until you’ve confirmed password‑less login works for your new user, then test a fresh connection from another terminal before closing the root session.
4. Set the timezone
sudo timedatectl set-timezone Continent/City
# Example: sudo timedatectl set-timezone Asia/Tokyo
5. Configure the FQDN
Edit /etc/hosts and replace the default line and add your public IP:
127.0.1.1 machinename.example.com
your.machine.ip.000 machinename.example.com machinename
Then set the system hostname:
sudo hostnamectl set-hostname machinename.example.com
6. Install WordOps
wget -qO wo wops.cc && sudo bash wo
source /etc/bash_completion.d/wo_auto.rc
echo -e "alias wo='sudo -E wo'" >> $HOME/.bashrc
7. Install and configure UFW (firewall)
wo stack install --ufw
wo secure --ssh
Before enabling UFW, ensure you allow SSH (already handled by wo secure --ssh), then enable the firewall:
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
For Cloudflare‑aware IP allowlisting, follow this other article:
8. Cloudflare API variables (for automation scripts)
export CF_Key="yourCloudflareAPIKey"
export CF_Email="yo*****************@*****le.com"
Persist these in ~/.bashrc or a dedicated env file if your automation needs them on every login.
9. Enable WordPress cron via system cron
Edit the root crontab:
sudo crontab -e
Add:
*/2 * * * * find /var/www -type f -name "wp-cron.php" -path "*/htdocs/wp-cron.php" -execdir sudo -u www-data php {} \; > /dev/null 2>&1
Make sure the
cronservice is running:sudo systemctl enable --now cron
10. Miscellaneous tools
# S3 command‑line tool
sudo apt update
sudo apt install -y s3cmd
# Configure with: s3cmd --configure
# Disk usage analyzer
sudo apt install -y ncdu
11. Redis (object cache)
Enable and start Redis as a system service:
sudo systemctl enable redis-server.service
sudo systemctl start redis-server.service
Verify with:
sudo systemctl status redis-server.service
12. WordOps modules we skip by default
- Nginx Ultimate Bad Bot Blocker: Great tool, but redundant when you’m already using Cloudflare’s WAF and rate limiting.
13. Final steps & next guides
Follow the dedicated guides complete the stack (reasons for each choice and alternatives are covered in those articles).
After these steps, your Ubuntu Server LTS box will have:
- A secure non‑root sudo user with SSH key access
- Root login disabled over SSH
- Correct FQDN and timezone
- WordOps + UFW + Cloudflare integration
- System‑level WP‑Cron, Redis, and common admin tools
You’re now ready to create WordPress sites with wo site create example.com --wpfc (or other stack options) and harden each site individually.
- How to Auto‑update UFW rules with Cloudflare IPs
- How to Install and Configure ClamAV to scan your server regularly for malware
- How to Install and Configure Fail2Ban to Secure Access to your VPS
- How to Install and Configure Monit to Watch and Monitor your Servers
- How to Install and Configure Sendmail to Use Any Email Provider as Your SMTP Relay
- How to Install and Configure Tarsnap to safely backup your sites
Leave a Reply