Profile-based automation with VPS-safe security hardening, network protection, and package management. Built for production servers.
Built for system administrators who value security, reliability, and automation. Every hardening option is VPS-safe by default.
Security defaults prevent remote lockout. Root SSH enabled, password authentication allowed by default for emergency access.
5 server profiles with 10 inheritance-based app profiles for targeted package management.
9 network hardening components. Enable exactly what you need with individual flags.
Two-layer architecture: server behavior + package selection with cumulative inheritance.
Configure overall server behavior:
Cumulative package inheritance:
Server profiles automatically choose appropriate package sets:
--server-profile default → server packages (36)--server-profile prod → server packages (36)--server-profile dev → full packages (57)--server-profile hardened → defense packages (47)Download the script, review it, run it with your preferred profile. No installer, no packages, no complex setup required.