Hardening a Dedicated Odoo Server (VPS or On-Premise): An Infrastructure Blueprint

Hardening a Dedicated Odoo Server (VPS or On-Premise): An Infrastructure Blueprint – Mediod Consulting Odoo Security guide cover

Running Odoo on your own server — a VPS on AWS, DigitalOcean or Google Cloud, or hardware in your own data centre — gives you full root access and complete freedom over the architecture. It also means you carry 100% of the security responsibility.

A new Linux server on the public internet sees automated port scans and password-guessing attempts within minutes. Hardening is not optional. This is the blueprint Mediod uses for self-hosted Odoo. This article is part of our Odoo security series.

Key takeaways

  • Never expose PostgreSQL (port 5432) or Odoo’s own port to the internet; put Nginx in front.
  • Use SSH keys only, disable root login and add fail2ban.
  • Set a strong master password and hide the database manager in production.
  • Keep encrypted backups off the server and test restores.

Common infrastructure weaknesses

  • Open database ports: PostgreSQL listening on all interfaces invites remote password guessing.
  • Default SSH settings: password logins on port 22 are the first thing bots try.
  • Unprotected database manager: a weak or default master password lets anyone with the URL back up, duplicate or drop your databases.
  • Unencrypted local backups: dumps and filestore copies sitting on the same disk, readable by other users.
  • Verbose errors: tracebacks and debug mode exposing internal details to visitors.

The hardening blueprint

1. Lock down SSH

Disable password authentication and allow key-based logins only. Disable direct root login, use a named sudo user, and allow SSH only from known IP addresses where you can.

2. Keep PostgreSQL private

In postgresql.conf, set listen_addresses = 'localhost' (or the private network address if the database sits on its own server), restrict pg_hba.conf to the Odoo host, and give the Odoo database user no superuser rights.

3. Harden the Odoo configuration file

  • Set a long, unique admin_passwd (the master password).
  • Set list_db = False and a dbfilter so the database manager and selector are not public.
  • Bind Odoo to localhost and enable proxy_mode when it runs behind a reverse proxy.
  • Run Odoo as its own unprivileged system user, and keep the config file readable only by that user.

4. Put Nginx in front

Terminate SSL in Nginx, redirect HTTP to HTTPS, add security headers (HSTS, X-Content-Type-Options, a referrer policy) and rate-limit /web/login to slow down password guessing. Block /web/database from the internet.

5. Add intrusion prevention

Configure fail2ban to watch SSH and Odoo login failures and ban repeat offenders. Enable a host firewall (ufw or firewalld) that only allows ports 22, 80 and 443.

6. Encrypt and test backups

Back up both the PostgreSQL database and the filestore, encrypt them, and copy them to a different provider or location. Restore a backup to a test server regularly — a backup you have never restored is a guess, not a plan.

7. Patch and monitor

Apply OS and Odoo source updates on a schedule, monitor disk, memory and login failures, and alert someone when something looks wrong.

How Mediod can help

Self-hosting needs ongoing DevOps work. Mediod sets up hardened Odoo servers, automated encrypted backups and monitoring, and looks after them through our support and maintenance plans. Moving an existing server? Our migration team can rebuild it on a hardened base.

More from our Odoo security series

See all Odoo Security articles →

Want a second pair of eyes on your Odoo security?

Mediod Consulting is an Official Odoo Partner. We review custom modules, access rights, integrations and hosting set-ups, and give you a prioritised list of fixes. Book a free discovery call or request a quotation for a security review.

FAQs

Frequently Asked Questions

Should PostgreSQL be reachable from the internet for Odoo?

No. PostgreSQL should only accept connections from the Odoo server itself, either on localhost or a private network.

How do I hide the Odoo database manager?

Set list_db = False and a dbfilter in the Odoo configuration file, use a strong master password (admin_passwd), and block /web/database at the reverse proxy.

Do I need Nginx in front of Odoo?

For production, yes. A reverse proxy such as Nginx handles SSL, security headers and rate limiting, and Odoo runs with proxy_mode enabled behind it.

Ayesha Wajid avatar

Ayesha Wajid

Ayesha Wajid writes about Odoo ERP implementation, business process automation, and digital transformation at Mediod Consulting.

Leave a Comment

Your email address will not be published. Required fields are marked *