Your provider emails an IP address, a root password, and nothing else. No wizard, no dashboard tour, no obvious next click. That blank terminal is where most people start searching for how to set up a VPS, and where most guides begin explaining hypervisors instead of telling you what to type.
Quick Answer: Setting up a VPS takes about 45 minutes. Deploy a Linux image (Ubuntu 26.04 LTS or 24.04 LTS), log in over SSH using the IP and root password your provider sent, run a full package update, create a sudo user, add an SSH key and then switch off password logins, allow only ports 22, 80 and 443 through the firewall, install your web stack, and point your domain's A record at the server IP.
Last verified: September 2026, against Ubuntu 26.04.1 LTS (Resolute Raccoon), Ubuntu 24.04.5 LTS, PHP 8.5, and the current Nginx, UFW and Let's Encrypt documentation.
Written by the Hostaccent Team, engineers at a UK-registered host (Companies House 11431799) that has run client servers since 2016 and incorporated in the UK in 2018.
Our engineers clear 20 to 30 client server issues a day, and plenty of them start on a box exactly like yours: fresh, empty, and one careless config edit away from locking out its owner. This vps setup guide follows the order that queue taught us.
Before You Touch the Terminal: What Your First VPS Actually Needs
You need four things before the first login: a Linux image, an SSH client, access to your domain's DNS records, and an answer to the question of who patches this server. A first VPS with 2 GB of RAM and 2 vCPUs comfortably runs a WordPress site, a small store, or a handful of staging environments. NVMe SSD speed matters more than raw storage size at this tier.
Pick the operating system first. Ubuntu LTS is the safest default, mostly because almost every tutorial you will ever read assumes it. Ubuntu 26.04 LTS arrived in April 2026 with security maintenance through 2031, while 24.04 LTS runs to May 2029 and still has the wider pool of third-party packages. Both are fine choices. Canonical publishes the full support calendar if you want exact dates before you commit.
Your SSH client is already installed. On macOS and Linux, open Terminal. On Windows 10 and 11, open Terminal or PowerShell and use the built-in ssh command. PuTTY still works, but you no longer need to download anything.
Decide the control panel question now, because it changes your budget. A cPanel or Plesk licence is commercial software with a real monthly cost, roughly $30 or more per month for cPanel at list pricing, which is more than most entry-level VPS plans. Any sub-$10 server advertising a free panel is paying that licence somewhere, usually through oversold hardware or a renewal jump. With full root access you can install a free panel, or run no panel at all.
Who patches this server? On an unmanaged plan, you do: kernel updates, PHP upgrades, all of it. On a managed plan, the host does. Neither answer is wrong. Pretending the question does not exist is how servers end up two years behind on security patches.
One last check before you deploy: does your provider offer snapshots? A snapshot of a clean, updated server is a free rollback point, and it is the cheapest insurance in this entire guide.
Pro Tip: Save your server IP, the root password and your chosen sudo username in a password manager before you begin. In our experience, the most common ticket from a brand new server is not a broken service. It is someone who hardened SSH from memory and locked themselves out at step seven.
How to Set Up a VPS in Eight Steps
Work through these in order. Steps one to four take roughly 10 minutes, and step five onwards is where the real work sits. Every command below assumes Ubuntu, and everything from step five is run as your new sudo user rather than root.
1. Deploy the image. In your provider's panel, choose Ubuntu 26.04 LTS (or 24.04 LTS), pick the datacenter closest to your visitors, and deploy. Provisioning usually finishes in 60 to 120 seconds.
2. Log in for the first time.
bashssh root@your_server_ip
Type yes at the fingerprint prompt, then paste the root password. A bare prompt means you are in.
3. Update everything.
bashapt update && apt upgrade -y
If the file /var/run/reboot-required exists afterwards, run reboot and reconnect a minute later.
4. Set the hostname and timezone.
bashhostnamectl set-hostname srv1.yourdomain.com timedatectl set-timezone UTC
UTC saves you confusion every time you read a log file across timezones.
5. Create a user who is not root.
bashadduser yourname usermod -aG sudo yourname
6. Add your SSH key, then test it. On your own machine, not the server:
bashssh-keygen -t ed25519 -C "laptop" ssh-copy-id yourname@your_server_ip
Now open a second terminal window and log in as that user. Leave the first window connected. This is the test that prevents lockouts, and it is the step the competing guides skip.
7. Turn off password and root logins. Only once step six works:
bashsudo nano /etc/ssh/sshd_config.d/99-hardening.conf
Add PermitRootLogin no and PasswordAuthentication no, save, then run sudo systemctl restart ssh. Confirm the second window still responds before you close the first.
8. Raise the firewall.
bashsudo ufw allow OpenSSH sudo ufw allow 80,443/tcp sudo ufw enable
Verify it worked: sudo ufw status should list OpenSSH and 80,443 as allowed, and a fresh ssh yourname@your_server_ip should log you in with no password prompt. Fix anything broken now, while you still hold a working session. For the next layer, our Linux VPS Security Baseline (Ubuntu 24.04) in 30 Min picks up where step eight stops.
Still working through this server issue?
Send the symptoms, error output, and what you have already tried. We can work with Hostaccent services or infrastructure hosted with another provider.
The 20-Minute Lockdown: Securing Your Server Before It Gets Found
Automated scanners find a new IP address within hours of it going live, so the gap between deployment and hardening is the dangerous part. According to Hostaccent's own support-queue data for 2026, brute-force and malware incidents account for about 25% of monthly tickets, second only to WordPress problems at 30%. Nearly all the server-side cases trace back to password logins that were never switched off.
We call the four steps below the 20-Minute Lockdown, because that is honestly how long they take on a fresh box.
1. ssh key authentication only. Step seven above covers it. This single change removes the entire brute-force attack surface. Keep the private key on your own machine and never send it by email.
2. A firewall with three rules. Deny inbound by default, allow SSH, allow 80 and 443. Run sudo ufw status numbered to see exactly what is open, and resist the urge to open database ports to the world.
3. Fail2ban for the noise.
bashsudo apt install fail2ban -y sudo systemctl enable --now fail2ban
4. Automatic security updates.
bashsudo apt install unattended-upgrades -y sudo dpkg-reconfigure --priority=low unattended-upgrades
Do I actually need a control panel on my first VPS?
Probably not, and this is where beginners overspend. A panel is a convenience layer for managing many sites and many users at once. For one or two sites, three commands and a text editor do the same job with less software running on the server. Our team runs client fleets both ways, and the pattern we see is that solo site owners who skip the panel spend less and break less. Root access means you can add one later without rebuilding.
Rate limiting is the layer most people add far too late, usually after the first bot flood. Nginx Rate Limiting: Basic DDoS & Bot Protection walks through the rules worth having in place beforehand.
Insider Insight: Moving SSH off port 22 is not security, it is noise reduction. It shrinks your auth log and nothing else. Do it if you like tidy logs, never as a substitute for key-only authentication.
Installing the Web Stack and Pointing Your Domain
A working site needs three pieces: a web server, an application runtime, and a certificate. Nginx with PHP-FPM is the combination we run in production behind Cloudflare, and on 2 GB of RAM it handles far more concurrent visitors than Apache on its own. Install both with sudo apt install nginx php-fpm -y, then build one server block per site.
PHP 8.5 is the current stable branch, and 8.4 stays in active support until the end of 2026, so pick one of those for anything new rather than inheriting whatever a tutorial from 2022 suggested. The official PHP version table shows what is still patched.
Point your document root at /var/www/yourdomain, enable caching headers for static files, and test the config with sudo nginx -t before every reload. Nginx's own documentation is the reference worth bookmarking.
Then DNS. In your registrar or Cloudflare dashboard, create an A record pointing the domain at your server IP, plus a second A record for www. Set the TTL to 300 seconds while you test, then raise it to 3600 once the site is stable. Propagation is usually minutes, not the 48 hours older guides still promise.
Then the certificate.
bashsudo apt install certbot python3-certbot-nginx -y sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com
Certbot edits the Nginx config and schedules renewal for you. Let's Encrypt documents the renewal behaviour if you want to understand what the timer does.
Verify before you celebrate. Load the site over HTTPS, then confirm that Nginx and your php-fpm service are enabled at boot, not merely running right now. Reboot the server once and reload the page. A stack that survives a reboot is a stack you can leave alone.
Running Node instead of PHP? Deploy Node.js App on Linux VPS: PM2 + Nginx Beginner Guide covers the same ground with PM2 in front. Once your site loads, Nginx + PHP-FPM Performance Tuning on Linux VPS explains the worker and pool settings that genuinely move page performance.
Five Mistakes That Break a First VPS
Most first-server disasters are ordinary. Across the 4,000+ site migrations Hostaccent has handled since 2016, the same five mistakes drive the bulk of emergency tickets, and every one of them is avoidable inside the first hour of owning the server.
Editing the SSH config with only one terminal open. Still the number one cause of a dead box. Two windows, every time.
No backups, because the provider has snapshots. A snapshot living on the same platform is not a backup. Pull a copy offsite on a schedule with Linux VPS Backup Automation with Rsync + Cron. We have run full restores under real pressure, including after hardware failure, and the ones that go smoothly are always the ones tested while nothing was on fire.
Ignoring disk and inode usage. df -h and df -i take two seconds to run. We have handled disk-full emergencies where every site on a server dropped at once, and the log files that filled the disk had been growing quietly for months.
No swap on a 2 GB box. A 2 GB swap file stops the kernel from killing your database during a traffic spike. It costs nothing and has rescued more client sites than any tuning parameter we have ever changed.
No monitoring. You want to hear about a problem from an alert, not from a customer: Setup Server Monitoring on VPS.
Once you configure a VPS this way, the weekly routine is short. Check updates, check disk, confirm a backup restored somewhere, glance at the auth log. Ten minutes on a Monday.
Pro Tip: Take a snapshot immediately after the lockdown and label it "clean base". When an install goes sideways three weeks later, rolling back to a hardened empty server beats rebuilding from scratch.
Your Next Step: A Server With Real Engineers Behind It
You now know how to set up a VPS end to end, from the first SSH login to a live certificate and a working DNS record. You can run that on anyone's hardware this weekend, or start on a stack where the tedious parts are already handled. The Basic plan at $7.99/mo gives you full root access, free 30 Gbps DDoS protection, a 99.99% uptime guarantee, and 24/7 help from our own engineers, at the same flat price when it renews. One honest caveat: no VPS at this price includes a cPanel or Plesk licence, ours included, so budget separately if you want a panel. If that suits you, start on the Basic VPS plan, backed by a 30-day money-back guarantee. That is the whole offer from Hostaccent.
Frequently Asked Questions About Setting Up a VPS
Do I need to know Linux before learning how to set up a VPS?
No, but you do need to copy commands accurately and read error messages instead of ignoring them. The eight steps above are the whole beginner path, and none of them require you to write a script. Five commands make you functional: ls, cd, nano, systemctl status and df -h. In the tickets we see, people rarely get beaten by Linux itself. They get beaten by skipping the SSH key test in step six.
How long does the first VPS setup take?
Budget about 45 minutes to reach a secured, empty server, then another 30 to 60 minutes to get a site loading over HTTPS. Provisioning itself finishes in 60 to 120 seconds. DNS is the variable, though at a 300 second TTL it usually resolves within minutes. If you are also migrating an existing site and database, add an hour and schedule it for your quietest traffic window.
Do I need cPanel or Plesk on a VPS?
No. A commercial panel licence runs roughly $30 or more per month for cPanel at list pricing, which frequently costs more than the server underneath it. Panels earn their keep when you manage many sites or resell hosting to clients. For one or two sites, Nginx plus Certbot does the same work with less software to patch. Root access means you can add a panel later without rebuilding anything.
What size VPS should a beginner start with?
Start with 2 GB of RAM, 2 vCPUs and NVMe SSD storage. That comfortably runs a WordPress site, a small WooCommerce store, or several staging environments at once. Resizing upward is usually a reboot rather than a migration, so paying today for headroom you might need next year is wasted money. Watch actual RAM and disk usage for a month, then size on evidence instead of guesswork.
Can I move my existing website to a VPS myself?
Yes, and the order matters more than the tooling. Copy the files, export and import the database, test the site on the new server through your local hosts file, and only then change DNS. Drop your TTL to 300 seconds the day before so the switch happens fast, and keep the old hosting alive for a week afterwards. Migrations that go wrong are nearly always the ones where DNS moved first.
What happens if I lock myself out of my VPS?
Your provider's console or VNC access gets you back in, because it connects beneath the SSH layer entirely. Log in there, correct the file in /etc/ssh/sshd_config.d/, then restart SSH. If no console is available, a snapshot rollback is the fallback, which is exactly why taking one right after hardening matters. Lockouts are recoverable in almost every case, so resist the urge to rebuild the server in a panic.












Discussion
Have a question or tip about this topic? Share it below — your comment will appear after review.