V-Server Setup
This page documents how I configured my very first cloud server instance in the Developer Akademie DevSecOps Course.
TOC
- Generate an SSH Key on Your Local Machine
- Connect to the V-Server
- Copy the SSH Key to the V-Server
- Disable Password Authentication
- Test Password Login (Should Fail)
- Reconnect Using SSH Key Authentication
- Install Nginx
- Configure Nginx to Forward Requests to Port 8081
- Add an Alternate HTML Page
- Set Up Git on the Server
URL: https://github.com/hpetersen2/V-Server-Setup
Checkout this repository to see the code/implementation
Description
In this project I set up my first V-Server from scratch as part of the Developer Akademie DevSecOps course. The goal was to get a small but properly secured server that can serve web content and pull code from GitHub.
The setup covers three areas:
- Secure access: Logging in with an SSH key pair (ed25519) and disabling password authentication, so brute-force attacks on the login no longer work.
- Web server: Installing Nginx and serving a custom HTML page on port 8081 through a separate server block.
- Git integration: Creating an SSH key on the server and registering it with GitHub, so the server can access repositories without a password.
The steps below are written so you can follow them in order on a fresh Linux server (Debian/Ubuntu).
1. Generate an SSH Key on Your Local Machine
ssh-keygen -t ed25519
- Specify the desired file path for the key pair.
- Optionally, protect your key with a passphrase.
2. Connect to the V-Server
ssh your-user@server-ip
Replace your-user and server-ip with your actual username and server IP address.
3. Copy the SSH Key to the V-Server
ssh-copy-id -i ~/.ssh/id_ed25519.pub your-user@server-ip
Note:
The commandssh-copy-idmust be installed on your system.
4. Disable Password Authentication
-
Navigate to the SSH configuration directory:
cd /etc/ssh/
-
Open the SSH configuration file:
sudo nano sshd_config
-
Find the line containing
PasswordAuthentication, uncomment it, and set the value tono:PasswordAuthentication no
-
Restart the SSH service:
sudo systemctl restart ssh.service
-
Exit the server:
logout
or
exit
5. Test Password Login (Should Fail)
Verify that password-based authentication is disabled:
ssh -o PubKeyAuthentication=no -i ~/.ssh/id_ed25519 your-user@server-ip
You should not be able to log in.
6. Reconnect Using SSH Key Authentication
ssh -i ~/.ssh/id_ed25519 your-user@server-ip
7. Install Nginx
Update the package list and install Nginx:
sudo apt update
sudo apt install nginx -y
The
-yflag automatically confirms the installation.
8. Configure Nginx to Forward Requests to Port 8081
Create a new Nginx configuration file:
sudo nano /etc/nginx/sites-enabled/alternatives
Insert the following configuration:
server {
listen 8081;
listen [::]:8081;
root /var/www/alternatives;
index alternate-index.html;
location / {
try_files $uri $uri/ =404;
}
}
Save and close the file.
Then restart Nginx to apply the changes:
sudo service nginx restart
9. Add an Alternate HTML Page
Create a new HTML file that Nginx will serve:
sudo nano /var/www/alternate-index.html
You can now access your page via port 8081 (e.g., http://your-server-ip:8081).
10. Set Up Git on the Server
1. Generate an SSH Key on the Server
ssh-keygen -t ed25519
Specify the file path for the key pair.
2. Display and Copy the SSH Public Key
Navigate to the directory where the SSH key was created, then run:
cat ~/.ssh/id_ed25519.pub
Copy the displayed SSH key.
3. Add the SSH Key to GitHub
- Log in to your GitHub account.
- Go to Settings → SSH and GPG keys.
- Click New SSH key.
- Enter a Title (e.g., "V-Server Access").
- Paste the copied SSH key into the Key field.
- Save the new SSH key.
Setup Complete
Your V-Server is now:
- Secured with SSH key authentication
- Configured with Nginx running on port 8081
- Ready to connect to GitHub via SSH