Checklist Keamanan VPS + Backup Website (Versi Ringkas + Versi Lengkap)

TL;DR

  • Minimal: update, firewall, SSH key, fail2ban, backup otomatis.
  • Jangan nunggu kejadian. Checklist ini dibuat biar kamu bisa audit cepat.

Versi Ringkas (15 menit)

  • [ ] Update OS packages
  • [ ] Nonaktifkan SSH password (pakai SSH key)
  • [ ] Ubah port SSH (opsional) + batasi IP kalau bisa
  • [ ] Aktifkan firewall (ufw): allow 22/80/443 seperlunya
  • [ ] Install fail2ban
  • [ ] Pastikan backup otomatis jalan (DB + files)
  • [ ] Cek disk space + log error

Versi Lengkap (Hardening)

1) SSH

  • [ ] PasswordAuthentication no
  • [ ] PermitRootLogin prohibit-password (atau no)
  • [ ] user baru untuk deploy

2) Firewall

  • [ ] allow hanya port yang dipakai
  • [ ] rate limit endpoint admin

3) Backup

  • [ ] backup database harian
  • [ ] backup folder upload/media
  • [ ] simpan offsite (S3/Backblaze)
  • [ ] test restore minimal 1x/bulan

4) Monitoring

  • [ ] uptime monitoring
  • [ ] alert disk penuh
  • [ ] alert 5xx

Baca juga

Related in