คู่มือความปลอดภัย DigitalOcean 2026 Firewall SSH และ Monitoring ครบจบ
DigitalOcean security guide 2026 — firewall setup, SSH hardening, two-factor auth, monitoring and incident response.
สารบัญ
ทำไม Security บน DigitalOcean ถึงสำคัญ
DigitalOcean ให้ Infrastructure ที่มีคุณภาพ แต่ Security ของ Droplet และ Application เป็นความรับผิดชอบของผู้ใช้งานเองตาม Shared Responsibility Model Server ที่เชื่อมต่ออินเทอร์เน็ตตกเป็นเป้าหมายของ Bot Scanner และ Brute Force Attack ตลอดเวลา การตั้งค่า Security ที่ดีตั้งแต่แรกช่วยลดความเสี่ยงได้อย่างมาก ประกอบด้วย Cloud Firewall, SSH Hardening, Two-Factor Authentication, Monitoring และการวางแผน Incident Response ที่ชัดเจน
DigitalOcean provides quality infrastructure, but Droplet and application security is the user's responsibility under the shared responsibility model. Internet-connected servers are constantly targeted by bot scanners and brute-force attacks. Configuring security correctly from the start dramatically reduces risk. A solid security posture on DigitalOcean includes Cloud Firewall rules, SSH hardening, two-factor authentication, active monitoring and a clear incident response plan. Each layer adds protection so that even if one control fails, others remain to limit the impact of any breach.
- DO ดูแล Physical Security ส่วน Droplet Security เป็นหน้าที่คุณ
- Server บนอินเทอร์เน็ตถูก Scan ตลอดเวลา
- Firewall + SSH Hardening ลดพื้นผิวโจมตี
ตั้งค่า Cloud Firewall และ UFW บน DigitalOcean
ข้อที่มักถูกมองข้ามคือ การตั้งค่า Firewall เป็นขั้นตอนแรกที่สำคัญสุดใน Security DigitalOcean Cloud Firewall ให้ตั้ง Inbound Rules เปิดเฉพาะ Port ที่จำเป็น เช่น 80, 443 สำหรับ Web และ SSH Port ที่เปลี่ยนจาก Default 22 แล้ว Block ทุก Port ที่ไม่จำเป็น บน Droplet ตัวเองควรติดตั้ง UFW เพิ่มเป็น Software Firewall ชั้นที่สองด้วย การมี Firewall สองชั้นทำให้หาก Misconfigure ชั้นหนึ่ง ยังมีอีกชั้นป้องกันอยู่ ควรตรวจสอบ Firewall Rules เป็นประจำและลบ Rule ที่ไม่จำเป็นออกเพื่อลด Attack Surface
- Cloud Firewall เปิดเฉพาะ Port 80, 443 และ SSH
- Block ทุก Port ที่ไม่จำเป็นทันที
- ติดตั้ง UFW เป็น Firewall ชั้นที่สองบน Droplet
- สร้าง Rule แยกสำหรับ Database Port
SSH Hardening บน DigitalOcean Droplet
SSH เป็นจุดเข้าหลักของ Server และมักเป็นเป้าหมาย Brute Force Attack การ Harden SSH ทำได้โดย เปลี่ยน Port จาก 22, ปิด Root Login, ใช้ SSH Key แทน Password, จำกัดจำนวนครั้งที่ Login ผิดได้ และติดตั้ง Fail2ban เพื่อ Block IP ที่โจมตีซ้ำ การตั้งค่าเหล่านี้ใน /etc/ssh/sshd_config ลด Attack Surface ของ SSH ลงได้อย่างมาก การรวม Non-standard Port กับ Key-only Authentication และ Fail2ban ทำให้ Bot ส่วนใหญ่ไม่สามารถโจมตีได้อย่างมีประสิทธิผล
- เปลี่ยน SSH Port จาก 22 เป็นพอร์ตสูง
- ปิด Root Login (PermitRootLogin no)
- ใช้ SSH Key เท่านั้น ปิด Password Auth
ตั้งค่า Two-Factor Authentication บน DigitalOcean
Two-Factor Authentication (2FA) สำหรับ DigitalOcean Account ป้องกัน Account ไม่ให้ถูกเข้าถึงแม้รหัสผ่านจะรั่วไหล เปิดใช้งาน 2FA ใน Account Settings ของ DigitalOcean โดยใช้แอป Authenticator เช่น Google Authenticator หรือ Authy นอกจาก 2FA บน Account แล้ว ควรพิจารณาใช้ Google Authenticator PAM Module สำหรับ SSH Login บน Droplet ด้วย เพื่อเพิ่มชั้นความปลอดภัยให้ SSH อย่าลืมบันทึก Recovery Code ไว้ในที่ปลอดภัยเผื่อสูญหาย Authenticator Device
- เปิด 2FA ใน DigitalOcean Account Settings
- ใช้ Google Authenticator หรือ Authy
- บันทึก Recovery Code ไว้ในที่ปลอดภัย
- พิจารณา 2FA สำหรับ SSH Login บน Droplet ด้วย
ตั้งค่า Monitoring และ Alert บน DigitalOcean
สิ่งที่น่าสนใจคือ digitalOcean Monitoring ให้ Metrics ของ Droplet เช่น CPU, RAM, Disk และ Network Usage พร้อม Alert ที่ตั้งค่าได้ เมื่อค่าเกินเกณฑ์ที่กำหนด นอกจาก DO Monitoring แล้วควรติดตั้ง Monitoring Stack เพิ่มเติม เช่น Prometheus + Grafana หรือ Datadog สำหรับ Visibility ที่ละเอียดกว่า Log Management ด้วยเครื่องมือเช่น Loki หรือ ELK Stack ช่วยตรวจสอบ Log เพื่อหาพฤติกรรมน่าสงสัย การรวม Resource Monitoring กับ Log Analysis ให้ Visibility ครบทั้งด้าน Performance และ Security ในภาพเดียว
- DO Monitoring Alert เมื่อ CPU/RAM เกินเกณฑ์
- ติดตั้ง Prometheus + Grafana เพิ่มเติม
- Log Management ด้วย Loki หรือ ELK Stack
- ตรวจ Log สำหรับ Failed Login ที่ผิดปกติ
Compliance และการปฏิบัติตามมาตรฐานบน DigitalOcean
DigitalOcean รองรับ Compliance หลายมาตรฐาน เช่น SOC 2 Type II, ISO 27001 และ PCI DSS ซึ่งช่วยให้ลูกค้าที่ต้องการ Compliance เหล่านี้สร้าง Application บน Platform ที่ได้รับการรับรองแล้ว อย่างไรก็ตาม Compliance ของ Application เองยังเป็นความรับผิดชอบของผู้ใช้งาน การใช้ VPC, Encryption at Rest และ Encryption in Transit เป็นส่วนหนึ่งของมาตรฐาน Compliance ทั่วไป ควรปรึกษาผู้เชี่ยวชาญด้าน Compliance ก่อนออกแบบ Architecture สำหรับระบบที่ต้องการ Certification เพื่อให้ครอบคลุมทุกข้อกำหนด
- DO รองรับ SOC 2, ISO 27001 และ PCI DSS
- Compliance ระดับ Application เป็นหน้าที่ของคุณ
- VPC + Encryption at Rest + TLS คือพื้นฐาน Compliance
วางแผน Incident Response สำหรับ DigitalOcean Infrastructure
Incident Response Plan คือแผนการรับมือเมื่อเกิดเหตุการณ์ Security บน Server การมีแผนที่ชัดเจนล่วงหน้าช่วยให้ Response ได้รวดเร็วและลดความเสียหาย ขั้นตอนพื้นฐานได้แก่ การตรวจจับ (Detection), การประเมิน (Assessment), การควบคุม (Containment), การกำจัด (Eradication) และการกู้คืน (Recovery) บน DigitalOcean ใช้ Snapshot เพื่อ Rollback ได้รวดเร็ว และใช้ Floating IP เพื่อย้าย Traffic ไปยัง Clean Server ได้ทันที
- มีแผน Incident Response ที่เป็นลายลักษณ์อักษร
- ขั้นตอน: ตรวจจับ → ประเมิน → ควบคุม → กำจัด → กู้คืน
- DO Snapshot ช่วย Rollback ได้รวดเร็ว
สรุปแนวทาง Security ที่ดีบน DigitalOcean
Security บน DigitalOcean ต้องลงมือตั้งแต่วันแรก ไม่ใช่คิดทีหลัง Cloud Firewall + SSH Hardening + 2FA + Monitoring + Incident Response Plan คือชุดพื้นฐานที่ทุก Droplet ควรมี การลงทุนเวลาตั้งค่าเหล่านี้ตั้งแต่แรกช่วยป้องกันปัญหาที่อาจเกิดขึ้นในอนาคตและลดความเสี่ยงที่จะถูก Compromise ได้อย่างมาก แนวทาง Defense-in-Depth ที่ทุก Layer ป้องกันแทนกันสร้าง Infrastructure ที่ยืดหยุ่นและน่าเชื่อถือในระยะยาว ทบทวนและอัพเดท Security Config เป็นประจำเพื่อรับมือกับภัยคุกคามใหม่ที่เกิดขึ้นอยู่เสมอ
- ตั้ง Security ตั้งแต่วันแรก ไม่ใช่ทีหลัง
- Cloud Firewall + SSH Hardening = พื้นฐานทุก Droplet
- 2FA ป้องกัน Account DO จาก Account Takeover