[{"data":1,"prerenderedAt":220},["ShallowReactive",2],{"navigation":3,"\u002Fnew-server-checklist":60,"\u002Fnew-server-checklist-surround":217},[4,8,12,16,20,24,28,32,36,40,44,48,52,56],{"title":5,"path":6,"stem":7},"Starter Server","\u002Fstarter-server","01.starter-server",{"title":9,"path":10,"stem":11},"How can I get more players to join my server?","\u002Fgetting-players","02.getting-players",{"title":13,"path":14,"stem":15},"What server software should I use?","\u002Fserver-software","03.server-software",{"title":17,"path":18,"stem":19},"What plugins are recommended when starting?","\u002Frecommended-plugins","04.recommended-plugins",{"title":21,"path":22,"stem":23},"How do I secure my server?","\u002Fserver-security","05.server-security",{"title":25,"path":26,"stem":27},"What server host should I pick?","\u002Fserver-hosting","06.server-hosting",{"title":29,"path":30,"stem":31},"Improving Server Performance","\u002Fserver-performance","07.server-performance",{"title":33,"path":34,"stem":35},"How much RAM do I need?","\u002Fhow-much-ram","08.how-much-ram",{"title":37,"path":38,"stem":39},"What is BungeeCord \u002F Waterfall \u002F Velocity?","\u002Fserver-networks","09.server-networks",{"title":41,"path":42,"stem":43},"How do I set up permissions?","\u002Fpermissions","10.permissions",{"title":45,"path":46,"stem":47},"What server management tool should I use?","\u002Fserver-management","11.server-management",{"title":49,"path":50,"stem":51},"How do I advertise my server?","\u002Fadvertising","12.advertising",{"title":53,"path":54,"stem":55},"Resources","\u002Fresources","13.resources",{"title":57,"path":58,"stem":59},"New Server Checklist","\u002Fnew-server-checklist","14.new-server-checklist",{"id":61,"title":57,"body":62,"contributors":202,"description":207,"editUrl":208,"extension":209,"links":210,"meta":211,"navigation":212,"path":58,"section":213,"seo":214,"stem":59,"updatedAt":215,"__hash__":216},"docs\u002F14.new-server-checklist.md",{"type":63,"value":64,"toc":194},"minimark",[65,70,102,106,125,129],[66,67,69],"h2",{"id":68},"server-optimization","Server Optimization",[71,72,73,82,85,94],"ul",{},[74,75,76,77,81],"li",{},"Install your server software of choice. Paper is a good default. Read more about server software in the ",[78,79,80],"a",{"href":14},"What server software should I use"," section.",[74,83,84],{},"Optimize your server.properties and .yml settings files (Celebrimbor’s\u002FBarty’s guides recommended)",[74,86,87,88],{},"Pre generate your worlds with ",[78,89,93],{"href":90,"rel":91},"https:\u002F\u002Fmodrinth.com\u002Fplugin\u002Fchunky",[92],"nofollow","Chunky",[74,95,96,97],{},"Launch your server using ",[78,98,101],{"href":99,"rel":100},"https:\u002F\u002Fdocs.papermc.io\u002Fpaper\u002Faikars-flags",[92],"Aikar’s flags",[66,103,105],{"id":104},"community","Community",[71,107,108,111,120],{},[74,109,110],{},"Create a Discord server to encourage community engagement",[74,112,113,114,119],{},"Avoid p2w and follow the ",[78,115,118],{"href":116,"rel":117},"https:\u002F\u002Fwww.minecraft.net\u002Fen-us\u002Feula",[92],"Minecraft EULA",".",[74,121,122,123],{},"Reliable places to advertise: see Reddit communities, server listings — and ",[78,124,49],{"href":50},[66,126,128],{"id":127},"security-system-administration-best-practices","Security & System Administration \u002F Best Practices",[71,130,131,134,137,140,143,146,149,152,155,164,167,170,173,176,179,182,185,188,191],{},[74,132,133],{},"Security works best in layers. No single layer, protocol, policy, or software will prevent an attack. The idea is to layer these things on top of each other to increase the cost of an attack beyond the capabilities of your threat actor.",[74,135,136],{},"Take regular off-site backups to prevent data loss. Use the 3-2-1 rule: 3 total copies, 2 different mediums, 1 offsite.",[74,138,139],{},"Periodically verify that your backups work. Backups are useless if you can’t restore them.",[74,141,142],{},"Don't give staff to people you don't know; always pick from your player base.",[74,144,145],{},"Follow the principle of least privilege. If someone doesn’t need access to something, then don’t give them access to it. This applies to both staff and players; additionally, this applies to ex-staff. Access control is important!",[74,147,148],{},"Always enable 2fa on any control panels or relevant sites.",[74,150,151],{},"Always keep in mind your bus factor. How many people (at minimum) in your organization can be suddenly hit and killed by a bus before the organization fails? If it’s one, then you may want to consider giving more people emergency access to your assets.",[74,153,154],{},"For best SSH security, firewall of the SSH port to the world and open it to only yourself. The most common method of doing this is to use a VPN to connect to an internal network which then has SSH access. This would, of course, require having the server on another internal network which you can then access.",[74,156,157,158,163],{},"If you use a VPS or dedicated server, make sure to lock down SSH with SSH keys, Fail2Ban, and a non-standard SSH port and give each server its own Linux user. Never run your servers as root! You can find a great guide by egg82 ",[78,159,162],{"href":160,"rel":161},"https:\u002F\u002Fgist.github.com\u002Fegg82\u002Fe7d4f8407d49470fb82ae82df2e3ef07",[92],"here","!",[74,165,166],{},"Keep things updated. This seems obvious, but all too often exploits are successful because of missing patches.",[74,168,169],{},"Firewalls are your friend. Restrict access to ports and\u002For IP address ranges to reduce the attack surface.",[74,171,172],{},"Think about your threat actor. You probably do not need to protect your Minecraft server against the NSA. What is the most likely type of person (and skill level) to attack your server? What would they want to accomplish? Defend against that.",[74,174,175],{},"When first starting out, you need to create a security policy. This can be as simple as “when I hit X number of concurrent players, I need to create a security policy”. Ultimately your security policy needs to, at minimum, consist of access control, incident response, asset management, and data integrity guidelines. How you accomplish those is up to you.",[74,177,178],{},"Mini tip: Providers such as OVH and Hetzner allow you to purchase multiple IP addresses for a server. This usually comes with the notion that the second IP will be on a separate network from the first, which will allow you to log into your server even if there’s an ongoing DDoS attack on it. The first IP is your “public” interface, and the second is your “private” interface allowing access for you only. This isn’t a magic bullet but could save your bacon a few times.",[74,180,181],{},"DoS and DDoS attacks are about cost. The idea behind them is to take down a target system without spending too much of your own time, money, or hardware on it. If you, as the defender, can make it so the cost of attacking you is very high then you will have very few attacks come your way.",[74,183,184],{},"Create documentation. Write down everything you’ve done from the very beginning. This will make it easier to create change control documentation later. I know; it’s hard, and it’s work. Take screenshots of what you’ve done, commands you’ve used, and links you’ve read and throw them into a word document. That will carry you until you or someone else can create proper documentation later.",[74,186,187],{},"Create a structure for the hiring and firing of staff. This will make your organization more resistant to certain types of phishing attacks and “I’m from Planet Minecraft”-type scams.",[74,189,190],{},"Two-factor authentication plugins such as 2FA+ will prevent attacks that take control of (or pretend to be) yourself or another staff account. In order for these types of systems to be effective against phishing attacks, they need to be truly two-factor; ie. “what you have”, which would be a phone or computer to generate time-based codes.",[74,192,193],{},"Got hacked? Find out who did it, what they were after or gained, when they performed each action, where (what systems) they attacked, why they did it, and how they performed the attack. Document that, and then create countermeasures against it for the future. Congratulations; you’ve done an incident response!",{"title":195,"searchDepth":196,"depth":196,"links":197},"",3,[198,200,201],{"id":68,"depth":199,"text":69},2,{"id":104,"depth":199,"text":105},{"id":127,"depth":199,"text":128},[203],{"name":204,"username":205,"avatar":206},"Sam Goodger","Turbotailz","https:\u002F\u002Fgithub.com\u002FTurbotailz.png?size=80","Optimization, community, and security\u002Fsystem administration checklist for a new Minecraft server.","https:\u002F\u002Fgithub.com\u002Fsyscraft-mc\u002Fsyscraft.dev\u002Fedit\u002Fmain\u002Fcontent\u002F14.new-server-checklist.md","md",null,{},true,"More",{"title":57,"description":207},"2026-09-22T09:51:47+10:00","mdyNOzFgPeVWBFwuF-3yiunJEspZvngtzdFzNPXiNaQ",[218,210],{"title":53,"path":54,"stem":55,"description":219,"children":-1},"External guides and Discord servers collected in the Syscraft FAQ.",1790034766447]