Security

UFW firewall

UFW: deny incoming by default, allow SSH + chosen ports. Destructive: keeps SSH open.

A recipe is not a frozen script: it is a verified playbook that drives an AI run. Reconnaissance first, idempotent by design, and every step proves itself before the next one starts.

Category
Security
Risk
destructive
Verified steps
4
Estimated
~2 min
Systems
Ubuntu · Debian
01

Reconnaissance — before touching anything

The run starts read-only. Before a single change, Servor checks the real state of your server — a real machine is rarely clean, and only what is actually there decides what happens next.

  • 01UFW installed? already active?
  • 02which ports are listening (so as not to cut them off)?
02

The steps — each one proves itself

The playbook below guides the run; the model adapts each command to the distribution and state found during reconnaissance. A step only counts as done when its verification passes.

  1. 01

    Install UFW

    Verified by

    command -v ufw
  2. 02

    Allow SSH BEFORE anything

    Verified by

    ufw status | grep -ci ssh
  3. 03

    Deny incoming by defaultdestructive

    Verified by

    true
  4. 04

    Enable the firewalldestructive

    Verified by

    ufw status | head -1
03

Variables

What you choose before launching — the recipe fills in the rest.

${ports}
Ports to open (besides SSH)
04

How Servor runs this recipe

Servor is zero-knowledge: the platform cannot execute anything on its own. When you launch this recipe, an AI run reads the reconnaissance, plans the steps, and asks for your approval. Each approved command is signed by your browser — with a key the server never sees — then relayed to the agent, which verifies the signature locally before executing.

  • Read-only reconnaissance before any change
  • Every command signed by your browser, approved by you
  • Each step verified before the run moves on

Run this recipe on your server

Connect a server, launch the recipe, and approve each step as Servor executes and verifies it. Free plan, no card required.