All guides
Getting started
VPS
- VPS operating systems
- VPS snapshots and
off-site backups - How to host your own VPN on a VPS with WireGuard
- How to run a Tor relay, bridge or onion service on a VPS
- How to
self-host BTCPay Server on a VPS - How to run a Bitcoin or Monero node on a VPS
Dedicated servers
- Using IPMI and the KVM console on a dedicated server
- Choosing a RAID layout for your dedicated server
Windows RDP
Windows Server 2019 , 2022 or 2025 vsWindows 10 and 11 for RDP- How to connect to a Windows RDP server from any device
GPU servers
Security
On this page
Every Offshore VPS is a KVM virtual machine with full root access. You pick an operating system template when you order, and you can change it at any time: reinstall from another template, or boot your own ISO and install any system that runs on
Available templates
| Template | Type | Security support |
|---|---|---|
| Current stable release, since | Regular support until about 2028, then LTS until | |
| Previous stable release | ||
| Standard support until | ||
| Standard support until | ||
| Compatible with Red Hat Enterprise Linux 9 | Until | |
| Compatible with Red Hat Enterprise Linux 9 | Until | |
| Arch Linux | Rolling release | Continuous, as long as you update often |
| BSD, stable branch | Branch supported until | |
| Alpine Linux | Minimal, | About two years per release branch |
The dates are the projects' own published plans as of
Reinstall from a template
- Back up your data to another machine. VPS snapshots and
off-site backups shows how with restic or Borg. - On your server's page in the client area, under Server actions, pick the template in Reinstall with, confirm that the disk will be erased and send the request. The new access details appear on the same page once the reinstall is done.
- Confirm. The new system is written to the disk and the VPS boots into it.
- Log in as root with the new credentials, install updates and work through the hardening guide again.
A reinstall creates new SSH host keys, so your SSH client will warn that the remote host identification has changed. Remove the old key from your computer, then connect again:
ssh-keygen -R SERVER_IP
Boot a custom ISO
Use your own ISO for systems that are not in the template list, such as OpenBSD, NixOS,
ip -br addr
ip route
- Find a direct HTTPS link to the ISO file on the publisher's official download page or mirror list, so you know the image is genuine. The link must download the file without a login or an intermediate page.
- On your server's page in the client area, under Server actions, choose Boot my own ISO and paste the link. Large images take a few minutes to fetch.
- We attach the ISO, set the VPS to boot from it and restart it. The request then shows as done, and the address and password of the VNC console appear in the Access section of the page.
- Open the VNC console. You now see the installer as if you were sitting at the machine.
- Install to the virtual disk, usually
on Linux or/dev/vda on FreeBSD. If the installer does not configure the network by itself, enter the IPv4 address, netmask and gateway you noted, and add an address from your /64 if you want IPv6.vtbd0 - When the installation finishes, request Detach the ISO and boot from disk under Server actions. Until it shows as done, a restart opens the installer once more.
KVM presents virtio disks and network cards. Current Linux and BSD installers include virtio drivers; Windows installers do not. If you need Windows, order a Windows RDP plan instead.
Notes on cloud-init
Some templates use
cloud-init status
If the command is not found, your system does not use
echo 'network: {config: disabled}' > /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg
If your hostname resets after a reboot, tell
echo 'preserve_hostname: true' > /etc/cloud/cloud.cfg.d/99-preserve-hostname.cfg
On Ubuntu, /etc/ssh/sshd_config.d/50-cloud-init.conf, which can switch password logins back on. The hardening guide uses a file that SSH reads before that one, so your settings win. To stop
touch /etc/cloud/cloud-init.disabled
Systems you install from your own ISO have no
Choosing an operating system
| Use case | Recommended | Why |
|---|---|---|
| Websites, reverse proxies, databases | Conservative updates, small base system, long support | |
| Docker and container hosts | Both are supported by Docker's own package repository | |
| Software certified for Red Hat Enterprise Linux | Binary compatible with RHEL 9, updates until 2032 | |
| Tor relay | The Tor Project publishes current packages for Debian | |
| WireGuard VPN | WireGuard is built into the Linux kernel | |
| Smallest footprint (Dinghy, | Alpine Linux or | A very small base system leaves memory for your application |
| ZFS, jails, pf firewall | All three are part of the base system | |
| Newest packages, for experienced users | Arch Linux | Rolling release: update often and read the Arch news before large upgrades |
| Older software that needs older libraries | Works today, but plan a move before support ends | |
| Windows applications | Windows RDP |
On the free -h
dd if=/dev/zero of=/swapfile bs=1M count=1024
chmod 600 /swapfile
mkswap /swapfile
swapon /swapfile
echo '/swapfile none swap sw 0 0' >> /etc/fstab
If you are unsure, choose
Dedicated and GPU customers can open a ticket from the client area with the server’s IP address and what they tried. First reply target: under