Servers and Cloud

Ubuntu Server Setup, Configuration and Ongoing Management

Installing Ubuntu Server takes a few minutes; the real work is planning the next five years of that server. We pick the right LTS release, harden the server and put updates, monitoring and backup in place.

CybUP TeamLast updated: 5 min read

In short

Ubuntu Server setup means installing a long-term support (LTS) release of Ubuntu on a physical or virtual server, hardening it through SSH and firewall settings, configuring automatic security updates and preparing it for web, application, database or Docker workloads. It is for companies that run Linux servers. CybUp delivers the installation together with hardening, monitoring and backup.

Which Ubuntu Server version should you install?

On servers we install LTS (Long Term Support) releases only. According to Canonical’s release cycle page, LTS releases come out every two years and get five years of standard security maintenance; Ubuntu Pro extends that to ten years, and the Legacy add-on to fifteen.

As things stand, standard maintenance for Ubuntu 22.04 LTS ends in May 2027, for 24.04 LTS in May 2029, and for 26.04 LTS, released in April 2026, in May 2031. For a new installation we choose between 24.04 and 26.04 based on which release the software you will run officially supports. If you still have 22.04 servers, the upgrade needs planning before 2027.

“LTS are released every two years and receive 5 years of standard security maintenance.”

— Canonical — Ubuntu release cycle

How do you harden Ubuntu Server?

We start hardening with SSH, because SSH is the first thing attackers go for on a Linux server reachable from the internet or a branch network. Following the settings in Ubuntu’s OpenSSH documentation, we switch to key-based authentication, disable password logins and direct root login, and make SSH reachable only from the management network.

Ubuntu’s default firewall tool is ufw, and according to the Ubuntu documentation it ships disabled. During setup we enable ufw, deny incoming traffic by default and open only the ports that are needed (22, 80, 443 or the database port, for example) to specific sources. On servers that need more complex rules, we write them directly in nftables. A host firewall does not replace the firewall on your network; the two work together.

  • SSH: key-based login, password and root login disabled
  • Default-deny rules with ufw or nftables
  • Unneeded services and packages removed
  • sudo rights granted per person and logged
  • Time synchronisation and central log collection

Can Ubuntu install security updates automatically?

Yes. On Ubuntu Server the unattended-upgrades package is installed by default and, according to the Ubuntu documentation, checks for and applies updates once a day. Which repositories updates come from, which packages are excluded and how reboots are handled are all defined in /etc/apt/apt.conf.d/50unattended-upgrades; automatic reboot is off by default.

We make this a deliberate decision for each server: nobody wants a database server rebooting itself in the middle of the night, whereas a web server may be fine restarting at a set time. To reduce the reboots needed for kernel updates, Canonical’s Livepatch service can be used; Livepatch is part of an Ubuntu Pro subscription. Ubuntu Pro is free for personal use on up to 5 machines; for company servers, Canonical sets the subscription terms.

“Ubuntu will apply security updates automatically, without user interaction. This is done via the unattended-upgrades package, which is installed by default.”

— Ubuntu Server documentation — Automatic updates

What is Ubuntu Server used for?

In companies, we most often see Ubuntu Server as a web and application server (Nginx, Apache, Node.js, PHP and Python applications), a database server (PostgreSQL, MySQL, MariaDB) or a Docker host. We plan the disk layout separately for each workload: if database files, logs and Docker data sit on separate partitions or LVM volumes, one of them filling up does not bring the whole server down.

Suppose an automation tool, a small internal web application and a PostgreSQL database are going to run in Docker containers. In that case we install Docker from the official repository, define the containers in Compose files, keep the database data in a named volume and expose only port 443 through a reverse proxy. Our n8n automation and local LLM deployments run on Ubuntu servers built this way too.

How do you monitor and back up Ubuntu Server after installation?

We install a monitoring agent on every Ubuntu server and feed disk usage, memory, service status, SSL certificate expiry and pending security updates into Zabbix monitoring. Getting an alert to the right person when a service stops or a disk passes 85 per cent is how you spot a problem before it grows.

For backup, we treat the whole server and the databases separately. For databases we take a consistent dump or an application-aware backup; for the whole server we plan image-level backups with Veeam Backup or a similar tool. We run a test restore before handover, because we do not trust a backup that has never been restored.

What you receive

  • LTS release choice and a note on the support timeline
  • Installed and hardened Ubuntu Server (SSH, ufw/nftables, user privileges)
  • Automatic update and reboot settings for each server
  • Web, database or Docker workload configuration
  • Monitoring agent, alert rules and a tested backup
  • Documentation of access details, ports and services

How we work

  1. 1

    Requirements

    We discuss the applications to be run, the access method and the volume of data.

  2. 2

    Installation

    We set up the LTS release, disk layout and network settings.

  3. 3

    Hardening

    We configure SSH, the firewall, user privileges and automatic updates.

  4. 4

    Workload

    We install the web, database or Docker layer and get the application running.

  5. 5

    Ongoing management

    We set up monitoring and backup, run a restore test and hand over.

Frequently asked questions

When should we upgrade our Ubuntu 22.04 server?

Standard maintenance ends in May 2027, so we recommend planning the upgrade before then. Ubuntu Pro can extend maintenance, but that is a subscription decision in its own right.

Do we need Ubuntu Pro?

No. The standard five years of security maintenance comes without Pro. Pro is worth considering when you need longer maintenance, Livepatch or compliance tooling.

Should the server be physical or virtual?

Either works. In most cases we install Ubuntu as a virtual machine on VMware, Hyper-V or Proxmox; for workloads that need a GPU, a physical server may be the better choice.

Do you set up Ubuntu servers remotely?

Yes. We carry out installation and hardening remotely anywhere in Türkiye, and work on site in Istanbul when needed.

How much does an Ubuntu Server setup cost?

We give you a written quote after reviewing the number of servers and the workloads they will run; the review is free.

Can you take over our existing Linux server?

Yes. We first review its configuration, open ports and patch status, and share what we find in writing. Then we plan the hardening and ongoing management steps with you.

Should we use Docker or install applications directly?

If several applications will share one server and they have official container images, Docker makes management easier. For something like a single database server, a direct install can be simpler.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.