Few Servers

The Few Servers starter kit: the first hour on a new server, tested

Eight scripts and two Compose stacks for a new Ubuntu VPS. Swap, key-only SSH, automatic updates, fail2ban, a firewall that also closes the ports Docker publishes, encrypted backups with a tested restore, and an audit you can run every month. Pay what you want, USD 9 suggested, for your whole team.

Get the kit (pay what you want, USD 9 suggested)

Why it exists

A fresh server with Docker on it has a problem most guides skip: ufw deny 8000 does not close a port that a container publishes. We wrote about it, then wrote the rules that do close it, then wrote a test that proves it on a fresh machine every time the kit changes.

What is inside

FileWhat it doesChanges the server?
scripts/00-preflight.shLooks at the server and tells you what is missingNo
scripts/10-swap.shAdds a swap file sized for the machine, permanentYes
scripts/20-ssh-harden.shKey-only SSH, with three guards against locking yourself out, and --rollbackYes
scripts/30-auto-updates.shSecurity updates install on their own; optional reboot timeYes
scripts/40-fail2ban.shBans addresses that keep failing SSH loginsYes
scripts/50-firewall.shufw for the host, plus rules in Docker's own chain for published portsYes
scripts/60-backup.shNightly restic backups of Docker volumes and Postgres dumps; restore commandsYes
scripts/90-audit.shPass, warn or fail for every item above; exit code for cron or monitoringNo
compose/uptime-kuma/Uptime Kuma 2.5.5, bound to localhost, one volume-
compose/n8n-postgres/n8n 2.41.5 with Postgres 16, health checks, generated secrets-
CHECKLIST.mdThe same steps as a one-page checklist-
TESTED.mdWhat was tested, where and when, and what was not-
tests/The test suite itself, so you can re-run it on a throwaway machine-

Tested, and how

Every script runs end to end on fresh Ubuntu 24.04 and 22.04 machines in an automated suite: it logs in over SSH before and after hardening, gets an address banned by fail2ban, checks from simulated outside addresses which ports answer, empties a Docker volume and restores it byte for byte from the backup, and starts both Compose stacks. On 2 Oct 2026 all 84 checks passed on both Ubuntu 24.04.5 and 22.04.5. The results and the limits are in TESTED.md, which ships in the zip.

What it is not

It does not install Docker or Coolify, issue certificates, or promise security. Ubuntu 24.04 and 22.04 only. You should be able to read a Bash script before you run it.

Price

Pay what you want: USD 9 is suggested, USD 0 is fine. One price for your whole team, any number of your own servers, free updates. Paid orders get a 14-day refund, no questions. Checkout and payment are handled by Polar, our merchant of record.

The kit's README has a short "Need a server?" section with our affiliate links to the hosts we have tested; they are marked as affiliate links, as everywhere on this site (how we make money).

FAQ

Does it work with Coolify? Yes: the firewall's default admin ports are Coolify's 8000, 6001 and 6002.

Can I use it on client servers? Yes, on servers you operate.

Is it a subscription? No. Pay once (or not at all), keep the updates.

Do I need to know Bash? Enough to read what a script will do before you run it.

Questions? hello@fewservers.com

Get the kit (pay what you want, USD 9 suggested)