Checklist Keamanan VPS + Backup Website (Versi Ringkas + Versi Lengkap)
TL;DR
- Minimal: update, firewall, SSH key, fail2ban, backup otomatis.
- Jangan nunggu kejadian. Checklist ini dibuat biar kamu bisa audit cepat.
Versi Ringkas (15 menit)
- [ ] Update OS packages
- [ ] Nonaktifkan SSH password (pakai SSH key)
- [ ] Ubah port SSH (opsional) + batasi IP kalau bisa
- [ ] Aktifkan firewall (ufw): allow 22/80/443 seperlunya
- [ ] Install fail2ban
- [ ] Pastikan backup otomatis jalan (DB + files)
- [ ] Cek disk space + log error
Versi Lengkap (Hardening)
1) SSH
- [ ]
PasswordAuthentication no - [ ]
PermitRootLogin prohibit-password(atau no) - [ ] user baru untuk deploy
2) Firewall
- [ ] allow hanya port yang dipakai
- [ ] rate limit endpoint admin
3) Backup
- [ ] backup database harian
- [ ] backup folder upload/media
- [ ] simpan offsite (S3/Backblaze)
- [ ] test restore minimal 1x/bulan
4) Monitoring
- [ ] uptime monitoring
- [ ] alert disk penuh
- [ ] alert 5xx
Baca juga
- Checklist keamanan VPS (artikel): https://semuaada.click/checklist-keamanan-vps-untuk-website-langkah-aman-yang-realistis/