Sysadmins of Mastodon, please share your knowledge with me! I have a Hetzner server set up that's running my website on a secondary domain. Before I fully make the transition, I want to make sure security is entirely correct. I have disabled root login and am only allowing access to the user account via SSH, I have a firewall up, and everything is updated. The internal code I've written should also be up to scratch.
What am I missing? I really want this to be as airtight as it can be.