LochStudios  /  Help Centre  /  VPS & Linux  /  First steps on a new VPS (update packages, create a sudo user)

First steps on a new VPS (update packages, create a sudo user)

Patch your new LochStudios KVM VPS, create a dedicated sudo user, and stop using root for everyday work.

Updated

A new LochStudios KVM VPS starts with a fresh OS image. Before you install a site or a stack, patch the packages and create a dedicated sudo user. Use that account for daily work. Leave root for recovery.

The IPv4, username, password, and an out-of-band console sit on that server in the portal. Sign in at the portal, open the VPS service, and copy the login from there. Do not guess a hostname.

Log in

  1. Sign in at the portal, open the VPS service, and copy the IPv4, username, and password.
  2. Connect over SSH. On a new VPS the user is often root.

- Windows: Connect to your VPS via SSH from Windows
- macOS or Linux: Connect to your VPS via SSH from macOS or Linux

If SSH from your PC will not connect, open the console on the same service. That session does not need port 22 from your network.

Update packages

If you are logged in as root, omit sudo from the commands below.

On Ubuntu or Debian:

sudo apt update
sudo apt upgrade -y

The -y flag accepts the package prompts. If the upgrade asks whether to restart a service, accept the default and press Enter.

On AlmaLinux, Rocky Linux, or similar:

sudo dnf upgrade -y

If sudo is missing (rare on our images), install it as root:

apt install sudo -y

Use dnf install sudo -y on AlmaLinux or Rocky Linux.

Reboot if the upgrade says a restart is needed:

sudo reboot

Wait about a minute, then SSH in again. Use the console in the portal if you would rather not wait on SSH.

Create a sudo user

Do not use root for daily work. Create a dedicated account and give it sudo.

  1. Create the user (Ubuntu or Debian):

```bash
sudo adduser youruser
```

Replace youruser with the name you want. Set a strong password when asked (at least 12 characters, mix of letters, numbers, and symbols). Confirm the password. You can press Enter to skip the Full Name and other fields.

On AlmaLinux or Rocky Linux:

```bash
sudo useradd -m youruser
sudo passwd youruser
```

  1. Grant sudo

Ubuntu or Debian:

```bash
sudo usermod -aG sudo youruser
```

AlmaLinux or Rocky Linux (the group is wheel):

```bash
sudo usermod -aG wheel youruser
```

The user can now run commands as root with sudo and their own password. This does not turn off the sudo password prompt.

  1. Test the new user

Disconnect (exit), then log in as the new user. Use the IPv4 from the portal:

```bash
ssh youruser@203.0.113.10
```

Then:

```bash
sudo whoami
```

If it prints root, the account is ready. After this, use this user for daily work.

Optional: disable root SSH login

Once the sudo user can log in over SSH, you can refuse root logins on port 22. Keep a second session open while you do this. If something goes wrong, use the console on the VPS service in the portal.

  1. Edit the SSH config:

```bash
sudo nano /etc/ssh/sshd_config
```

  1. Find PermitRootLogin. It may be yes, prohibit-password, or without-password. Change it to:

```
PermitRootLogin no
```

On newer Ubuntu images, a file under /etc/ssh/sshd_config.d/ may set this. Check that folder if the line is missing or commented out. Use Ctrl + W to search in nano.

  1. Save (Ctrl + X, then Y, then Enter) and restart SSH:

```bash
sudo systemctl restart ssh
```

On AlmaLinux or Rocky Linux, use sudo systemctl restart sshd.

  1. Before you close the current session, open a new terminal and log in as youruser. Only close the old session once that works.

What is next

Your VPS is patched and you have a dedicated sudo user. Recommended next steps:

Unsure about any of those steps? Open a support ticket and we will walk through it with you.

Troubleshooting

sudo: command not found

Install sudo as root (apt install sudo -y or dnf install sudo -y), add your user to sudo or wheel, then log out and back in so the group applies.

youruser is not in the sudoers file

You are not in the sudo (or wheel) group yet, or you have not logged in again after usermod. Add the group as root. Use the console on the VPS service in the portal if you already left the root SSH session. Then reconnect as youruser.

Cannot log in after disabling root

Do not keep trying as root. Open the console on the VPS service in the portal, log in there, and check /etc/ssh/sshd_config plus /etc/ssh/sshd_config.d/. Confirm PermitRootLogin and that your sudo user exists.

Still stuck? Open a support ticket. Tell us the VPS service, the IPv4, the username you used, and what you saw. Do not send the password in the ticket.


Was this article helpful?

← Back to VPS & Linux