# System and security

With root access, you administer your system: you install the software of your choice and you decide the schedule of its updates. Simafri operates the platform that carries it: the hardware, the network, anti-DDoS protection, backups and monitoring.

## Your system

Your VPS Pro is delivered with **Ubuntu 24.04 LTS**, or with **Debian 13** depending on your choice when ordering, up to date at the time it goes into service. To find out the installed version:

```
cat /etc/os-release
```

## Updates

Apply updates regularly:

```
apt update && apt upgrade
```

To have security fixes install themselves every day, enable **unattended-upgrades**:

```
apt install unattended-upgrades

dpkg-reconfigure -plow unattended-upgrades
```

Our monitoring flags the security updates that deserve your attention; you decide whether to apply them and when. Before a major update (a new version of the system, of your database or of your language), request a **snapshot** from support: it lets you roll back in a few minutes (see [Backups and snapshots](/en/vps-pro/sauvegardes.md)).

## Good practice

* **One SSH key per person**, added in your client area or in each person's account (see [Connecting over SSH](/en/vps-pro/connexion-ssh.md)).
* **A firewall** that opens only your public services (see [Network and sending email](/en/vps-pro/reseau-et-e-mails.md)).
* **One user per application**, without administrative rights, to run each service (`User=` in its systemd unit).
* **Your secrets outside the code**: passwords and API keys in a `.env` file readable only by the application (`chmod 600`).
* **Logs read from time to time**: `journalctl -p warning -b` shows the warnings since boot.

## The time zone

Your server is set to Coordinated Universal Time (UTC), the convention for servers. To display it in your time zone:

```
timedatectl set-timezone Europe/London
```

Your applications preferably keep their dates in UTC and convert them for display.

## Monitoring your server

A few commands to read the state of your server:

| Command              | What it shows                                     |
| -------------------- | ------------------------------------------------- |
| `htop`               | the processes, the processor and the memory, live |
| `free -h`            | used and available memory                         |
| `df -h`              | used and available disk space                     |
| `ncdu /`             | what takes up your disk, folder by folder         |
| `systemctl --failed` | the services stopped on an error                  |

Our monitoring continuously tracks your server's availability, its load and its disk space, and alerts you when one of these indicators calls for it.

## What Simafri does

| Simafri operates                                    | You administer                             |
| --------------------------------------------------- | ------------------------------------------ |
| the hardware and its mirrored disks                 | the system, its software and their updates |
| the network, the addresses and anti-DDoS protection | your firewall and your services            |
| the nightly backup                                  | your data and your database exports        |
| continuous monitoring                               | your applications and their configuration  |

And between the two, **Full-Stack Assistance**: for a question about the system, the database or your code, we diagnose it and tell you what to do (see [Full-Stack Assistance and hands-on intervention](/en/vps-pro/assistance.md)).
