Running Odoo on your own server — a VPS on AWS, DigitalOcean or Google Cloud, or hardware in your own data centre — gives you full root access and complete freedom over the architecture. It also means you carry 100% of the security responsibility.
A new Linux server on the public internet sees automated port scans and password-guessing attempts within minutes. Hardening is not optional. This is the blueprint Mediod uses for self-hosted Odoo. This article is part of our Odoo security series.
Key takeaways
- Never expose PostgreSQL (port 5432) or Odoo’s own port to the internet; put Nginx in front.
- Use SSH keys only, disable root login and add fail2ban.
- Set a strong master password and hide the database manager in production.
- Keep encrypted backups off the server and test restores.
Common infrastructure weaknesses
- Open database ports: PostgreSQL listening on all interfaces invites remote password guessing.
- Default SSH settings: password logins on port 22 are the first thing bots try.
- Unprotected database manager: a weak or default master password lets anyone with the URL back up, duplicate or drop your databases.
- Unencrypted local backups: dumps and filestore copies sitting on the same disk, readable by other users.
- Verbose errors: tracebacks and debug mode exposing internal details to visitors.
The hardening blueprint
1. Lock down SSH
Disable password authentication and allow key-based logins only. Disable direct root login, use a named sudo user, and allow SSH only from known IP addresses where you can.
2. Keep PostgreSQL private
In postgresql.conf, set listen_addresses = 'localhost' (or the private network address if the database sits on its own server), restrict pg_hba.conf to the Odoo host, and give the Odoo database user no superuser rights.
3. Harden the Odoo configuration file
- Set a long, unique
admin_passwd(the master password). - Set
list_db = Falseand adbfilterso the database manager and selector are not public. - Bind Odoo to localhost and enable
proxy_modewhen it runs behind a reverse proxy. - Run Odoo as its own unprivileged system user, and keep the config file readable only by that user.
4. Put Nginx in front
Terminate SSL in Nginx, redirect HTTP to HTTPS, add security headers (HSTS, X-Content-Type-Options, a referrer policy) and rate-limit /web/login to slow down password guessing. Block /web/database from the internet.
5. Add intrusion prevention
Configure fail2ban to watch SSH and Odoo login failures and ban repeat offenders. Enable a host firewall (ufw or firewalld) that only allows ports 22, 80 and 443.
6. Encrypt and test backups
Back up both the PostgreSQL database and the filestore, encrypt them, and copy them to a different provider or location. Restore a backup to a test server regularly — a backup you have never restored is a guess, not a plan.
7. Patch and monitor
Apply OS and Odoo source updates on a schedule, monitor disk, memory and login failures, and alert someone when something looks wrong.
How Mediod can help
Self-hosting needs ongoing DevOps work. Mediod sets up hardened Odoo servers, automated encrypted backups and monitoring, and looks after them through our support and maintenance plans. Moving an existing server? Our migration team can rebuild it on a hardened base.
More from our Odoo security series
- Custom Modules and Security Debt: Writing Safe Odoo Apps from Scratch
- Odoo.sh Security: What’s Handled for You and What You Still Need to Protect
See all Odoo Security articles →
Want a second pair of eyes on your Odoo security?
Mediod Consulting is an Official Odoo Partner. We review custom modules, access rights, integrations and hosting set-ups, and give you a prioritised list of fixes. Book a free discovery call or request a quotation for a security review.
Frequently Asked Questions
Should PostgreSQL be reachable from the internet for Odoo?
No. PostgreSQL should only accept connections from the Odoo server itself, either on localhost or a private network.
How do I hide the Odoo database manager?
Set list_db = False and a dbfilter in the Odoo configuration file, use a strong master password (admin_passwd), and block /web/database at the reverse proxy.
Do I need Nginx in front of Odoo?
For production, yes. A reverse proxy such as Nginx handles SSL, security headers and rate limiting, and Odoo runs with proxy_mode enabled behind it.



