I will set up and secure your linux vps with docker and coolify
About this Gig
A fresh VPS is an open door. I close it, then make it useful.
I run production infrastructure for a manufacturing company on Ubuntu 24.04: ERP, web apps, private internal services. This is the same setup I trust with real business data, not a copied tutorial.
Hardening included:
SSH key only auth on a non standard port, root login disabled
UFW firewall WITH the Docker bypass properly mitigated. Most setups leave your containers exposed to the internet even with a firewall running. This is the single thing people get wrong most often
Fail2ban, unattended security upgrades, swap and kernel tuning
Cloudflare in front: TLS 1.2 or higher, HSTS, bot protection
Automated backups, and a restore I test before handover
Then the platform: Docker and Coolify, so you deploy apps from a dashboard instead of logging in over SSH every time. Optional Tailscale, so your admin panels are reachable only by you and never exposed publicly.
You keep full root access and a written handover document. No lock in, no retainer.
Works on Hetzner, DigitalOcean, Vultr, Contabo, OVH, Linode, Lightsail.
Message me with your provider and RAM before ordering and I will confirm the fit.
Tools:
Docker
•
Other
Frameworks:
Other
Cloud Provider:
Digital Ocean
•
Other
Programming language:
Bash
•
Python
Expertise:
Installation
•
Debugging
•
Configuration
FAQ
Do you need my root password?
I need temporary root or sudo SSH access. I set up key-based login for you during the work, and you rotate the credentials the moment I hand over. I'll walk you through that step.
Will this take my site offline?
Not if you tell me it's there. Answer requirement Nª3 honestly and I stage everything with rollback ready.
Do I need to buy software?
Only the VPS and a domain. Every tool I install is open source and free. No licences, no monthly fees to me.
Can you manage the server after delivery?
Yes, order the 30-day support extra. After that we can arrange something ongoing, but nothing about my setup requires me to stay involved.

