This page gets you a server. You protect the OVH account first, make an SSH key just for this server, then order a VPS-1 running plain Debian 13 in a French datacenter with that key preinstalled, wait for the delivery email, note the two IP addresses, and log in once as debian. Most of it is clicks in the OVH control panel; the terminal comes in at the end.
Before you start
You need four things:
- An OVHcloud account, created on ovhcloud.com/fr. It gives you a customer ID (NIC handle, like
ab12345-ovh) and access to the control panel. - A payment method on that account: card, PayPal or SEPA direct debit.
- Your Mac, set up on page 1 (Prepare your laptop). The SSH key for the server is made on this page, right before the order form.
- Nothing about the domain: it stays registered and hosted at Infomaniak. You point it at the VPS on page 4, no transfer needed.
Protect the OVH account
Before ordering anything, turn on two-factor authentication. In the control panel, open your account (your initials, top right) → Security → Two-factor authentication, and add a method.
Three methods are offered: an authenticator app (TOTP), a security key (FIDO/U2F), or SMS. Prefer the app or a key; SMS is the weakest of the three. When the first method is added, OVH shows backup codes: store them in your password manager, next to the account password.
Make the server's SSH key
The order form asks for a public SSH key. Make it now, for this server only, in its own file ~/.ssh/id_ed25519_vps, with a passphrase. The command asks for the passphrase twice, so it runs on its own:
$ssh-keygen -t ed25519 -C "@-vps" -f ~/.ssh/id_ed25519_vpsStore the passphrase in the Keychain and load the key into the agent. It asks for the passphrase one last time:
$ssh-add --apple-use-keychain ~/.ssh/id_ed25519_vpsThen copy the public half, and paste it in the field Your server's public key of the values panel. Page 3 writes it from there into your own account on the server.
$pbcopy < ~/.ssh/id_ed25519_vps.pubThe line on your Mac and the one in the panel must be the same:
$cat ~/.ssh/id_ed25519_vps.pubChoose the model
On ovhcloud.com/fr/vps, pick VPS-1 and click Order. The range in September 2026:
| Model | vCores | RAM | NVMe disk | From, per month incl. VAT |
|---|---|---|---|---|
| VPS-1 | 2 | 4 GB | 40 GB | 4.57 € (3.81 € excl. VAT) |
| VPS-2 | 4 | 8 GB | 75 GB | 8.65 € |
| VPS-3 | 6 | 12 GB | 100 GB | 12.48 € |
| VPS-4 | 8 | 24 GB | 200 GB | 23.95 € |
VPS-1 is plenty. The site is static: Caddy reads files from disk and sends them. A few hundred visits a day use well under 1 % of one vCore. The 40 GB disk holds the system (about 2 GB), around 20 releases of the site (~217 MB each, and mostly hard-linked to each other, see page 6), the logs and local backups.
Pick the datacenter
In the order form, choose a location in France: Gravelines, Roubaix, Strasbourg or Paris, whichever is available for the model.
Pick the image: Debian 13
For the image, choose Debian 13 under the plain "distribution only" images. Do not take an image with Plesk, cPanel, Docker or an application preinstalled.
If only Debian 12 is offered, take it: every page of this series works the same on 12 and 13.
Add your SSH key
The order form has an optional SSH key field. Paste the public half of the key you just made there (the whole line, from ssh-ed25519 to @-vps) and name it, for example id_ed25519_vps. If the clipboard has changed since, copy it again:
$pbcopy < ~/.ssh/id_ed25519_vps.pubIf you already ordered without a key
Two ways on, pick one:
- Reinstall with the key. In the control panel, VPS page → Reinstall, choose Debian 13 again and paste the key into the SSH key field. It wipes the disk, which costs nothing on a server you have not used yet. The IP addresses stay the same; the host key changes (see "If ssh says REMOTE HOST IDENTIFICATION HAS CHANGED" below).
- Carry on with the password. Log in as
debianwith the password from the delivery email: ssh asks for it in "First login". Page 3 does not rely on the keys ofdebian: it writes the key from the values panel into your own account and checks it before passwords are refused. On this page, the first check of "First login" fails (it refuses passwords); the others ask for the password.
Options and commitment
Automated backup with one day of retention is included in the price: leave it on. The rest is optional:
- Premium backup, from about 1.32 € incl. VAT a month: keeps more days of backups. Not needed here; page 7 sets up backups of what matters.
- Snapshot, from about 0.36 € incl. VAT a month: one manual, point-in-time copy of the whole VPS that you can restore in one click. Take it: page 3 and page 7 use it before risky changes.
Delivery: IP addresses and password
Delivery usually takes a few minutes, sometimes a few hours. You get an email with the IPv4 address, the user name debian, and a secure link to the temporary password.
Then find both addresses in the control panel: Bare Metal Cloud → Virtual private servers → your VPS → Home, section IP. Copy the IPv4 and the IPv6 (without the /prefix).
Fill and in the values panel now. Every command from here on uses them.
First login
Log in as debian with the key made for this server:
$ssh -i ~/.ssh/id_ed25519_vps -o IdentitiesOnly=yes debian@-i names the server's key, and IdentitiesOnly=yes stops ssh from offering the other keys of this Mac first. Page 3 puts both into a vps shortcut; until then, you type them.
The first time, ssh shows the server's key fingerprint and asks whether to continue. Answer yes.
Confirm it is Debian 13 on the model you ordered, with sudo working. The first check refuses passwords, so it also proves the key works:
$ssh -i ~/.ssh/id_ed25519_vps -o IdentitiesOnly=yes -o PasswordAuthentication=no -o BatchMode=yes debian@ 'grep VERSION_CODENAME /etc/os-release'VERSION_CODENAME=trixie
$ssh -i ~/.ssh/id_ed25519_vps -o IdentitiesOnly=yes debian@ nproc2
$ssh -i ~/.ssh/id_ed25519_vps -o IdentitiesOnly=yes debian@ 'sudo -n true && echo OK'OK
On Debian 12 the codename is bookworm. On VPS-2 nproc prints 4.
Then check that the IPv6 address is configured on the server itself:
$ssh -i ~/.ssh/id_ed25519_vps -o IdentitiesOnly=yes debian@ 'ip -6 -brief addr show scope global'If no IPv6 address shows
On recent images OVH configures IPv6 at first boot. If the command prints nothing, follow the OVH guide "Configure IPv6 on a VPS" (docs.ovhcloud.com): on recent images it adds a netplan file, /etc/netplan/51-cloud-init-ipv6.yaml. Fix it before page 4, since a DNS AAAA record pointing at an address the server does not answer on is worse than no AAAA at all.
If ssh says REMOTE HOST IDENTIFICATION HAS CHANGED
Expected only if you reinstalled the VPS: the new system has a new host key. Remove the old one from your Mac, then log in again and accept the new one.
$ssh-keygen -R If you did not reinstall anything, stop and look at the console first.
Know your way back in
Three tools in the control panel save you when SSH does not. Find them now, while nothing is broken. All three are on the VPS page in the control panel:
- KVM console: the
...button next to the VPS name → KVM. A screen and keyboard attached to the VPS, in your browser. It works even with SSH down or the firewall closed. Log in with a password, never with a key. - Rescue mode: boots a small separate system and mounts your disk, so you can fix a broken file. The rescue credentials arrive by email.
- Reinstall: puts a fresh image on the VPS.
Open the KVM console once now and log in as debian with the temporary password. If it refuses, set a new password over SSH with sudo passwd debian and try again: you want this door tested before page 3.
Done
You have a Debian 13 VPS in a French datacenter, reachable as debian with the key made for it (~/.ssh/id_ed25519_vps), that key's public half, the IPv4 and the IPv6 in the values panel, the console tested, and an OVH account under two factors.
The server is already on the internet with SSH on port 22, and bots are already trying it. Go on to the next page, Secure the server in the first hour, now: it creates , moves SSH to port , refuses passwords and turns on the firewall.