
What is a VPS? It is a virtual private server: an isolated slice of a physical server in a data centre with its own operating system, IP address and root access, plus a fixed share of CPU, memory and storage. You manage it like a standalone machine but pay only for your portion of the hardware.
What is a VPS, in plain terms
Think of the three classic hosting options as housing. Shared hosting is a room in a shared house: the kitchen, the bathroom and the house rules are common, and you cannot move the walls. A dedicated server is a detached house: everything is yours, including the repair bills. A VPS is an apartment: you share the building with neighbours, but behind your front door you decide what goes where, and you have your own lock and your own address.
Under the hood, the provider runs a hypervisor on a powerful physical host. The hypervisor splits the host's processors, RAM, disks and network among several virtual machines. Each of them boots its own operating system — usually a Linux distribution such as Ubuntu, Debian or AlmaLinux, sometimes Windows Server — and from the inside looks like an ordinary computer. You can install any software, open ports, change system settings and reboot without opening a support ticket.
The trade-off is responsibility. On a standard (unmanaged) VPS nobody patches the OS, configures the firewall or takes backups for you. Freedom and duties arrive in the same box.
How virtualization shapes what a VPS can do
Two very different technologies are sold under the same "VPS" label, and the difference matters more than any number on the pricing page.
Full virtualization: KVM, VMware, Hyper-V
KVM is a Linux kernel module that uses the CPU's hardware virtualization extensions (Intel VT-x, AMD-V). VMware ESXi, Microsoft Hyper-V and Xen HVM work on the same principle. Every guest runs its own kernel, which means:
- you can run almost any OS, including Windows Server or FreeBSD, provided the host offers the image or lets you mount your own ISO;
- you can load kernel modules, tune the kernel with
sysctland upgrade it yourself; - Docker, WireGuard and custom nftables or iptables rules work without surprises;
- the memory limit behaves like real RAM: the guest sees its own total and manages it.
Container-based: OpenVZ and LXC
OpenVZ and LXC isolate groups of processes rather than whole machines. All containers on a host share the host's kernel. Overhead is lower, so these plans are often cheaper, but you give up a lot:
- Linux only, on whatever kernel version the host runs — you cannot change it;
- no custom kernel modules and only part of the
sysctltree; Docker and WireGuard may or may not work depending on host settings; - oversubscription is easier: a provider can sell more RAM and CPU time across containers than physically exists, and you feel it at peak hours.
A container is fine for a site on a standard LAMP or LEMP stack or a small bot. For Docker, a company VPN, or anything that touches the kernel, choose KVM.
Checking what you actually got
systemd-detect-virt
# prints kvm, openvz, lxc, vmware, microsoft, xen, ...
hostnamectl | grep -i virtualization
lscpu | grep -i hypervisor
An answer of openvz or lxc means you are in a container. On OpenVZ you will also find /proc/user_beancounters, the file with the container's resource counters.
VPS vs VDS: is there a difference?
VDS stands for virtual dedicated server. No standard separates the two terms: English-speaking providers almost always say VPS, while some European and Russian hosts use both words interchangeably. A few hosts use "VDS" for full virtualization and "VPS" for containers, but that is a marketing convention rather than a definition. Read the "virtualization" line on the plan page; if it is missing, ask before you pay.
VPS vs shared hosting vs dedicated server
| Shared hosting | VPS | Dedicated server | |
|---|---|---|---|
| Access | Control panel, SFTP, sometimes non-root SSH | Full root over SSH, or Administrator over RDP | Root plus out-of-band hardware access (IPMI, iLO, iDRAC) |
| Resources | Shared with many sites, capped per account | Allocated vCPU, RAM and disk within the plan | The whole machine |
| Software | Whatever the host installed | Anything compatible with the OS and virtualization type | Anything, including your own hypervisor |
| Who maintains the OS | The provider | You, unless you buy a managed plan | You |
| IP address | Usually shared | Dedicated IPv4, often IPv6 too | Dedicated, extra subnets on request |
| Scaling | Plan change in the panel | Plan change, usually with a reboot | New or added hardware, hours to days |
| Noisy neighbours | Real risk: one busy site slows the box | Reduced by the hypervisor; disk and network are still shared | None |
| Best for | Brochure sites, blogs, small CMS sites | Growing projects, custom stacks, services and workers | Heavy databases, high traffic, strict isolation |
Cloud servers deserve a note. A cloud instance is essentially a VPS running on a cluster with network storage: resizing is faster, billing is usually hourly, and if a physical node dies the instance can be restarted elsewhere. Where "VPS" ends and "cloud" begins varies by provider. A longer comparison, including the cost of picking the wrong tier, is in shared hosting vs VPS vs dedicated vs cloud, and the basics of hosting in general are covered in what web hosting is.
What you get with a VPS plan
- vCPU — virtual cores, typically hardware threads of the host shared with other tenants. Check whether the share is guaranteed or the figure is a burst ceiling.
- RAM — the usual bottleneck for databases, PHP-FPM, Node.js and the JVM. When it runs out, the kernel's OOM killer terminates the largest process, often the database.
- Storage — NVMe, SSD or HDD. Random I/O and per-VM I/O limits matter as much as capacity; on budget plans the disk tends to saturate before the CPU.
- Network — port speed, traffic allowance, IPv6, and whether basic DDoS filtering is included.
- A dedicated IP — needed for your own reverse DNS (PTR) record, which matters if the server sends mail.
- Root access — SSH on Linux, RDP on Windows.
- An out-of-band console (VNC or a web console) — your way back in after a firewall rule locks you out.
- OS images, snapshots, backups — reinstalls are standard; backups are often an add-on.
Managed vs unmanaged
An unmanaged VPS gives you a bare OS and nothing else. A managed plan adds OS patching, monitoring and often a control panel, at a higher price. If nobody on your team is comfortable at a Linux shell, managed is the safer default: an unpatched server with password SSH is found and probed by bots very quickly.
Verifying the resources
nproc # usable cores
free -h # memory and swap
df -h # filesystems and free space
lsblk # block devices
cat /etc/os-release # OS version
Watch steal time too: the share of time your VM wanted the CPU but the hypervisor gave it to someone else. It is the st field in the %Cpu(s) line of top and the last column of vmstat 1 5. If it stays clearly above zero under load rather than spiking now and then, the host is overcommitted and tuning your code will not fix it.
For disk performance, fio gives comparable numbers across plans:
fio --name=randread --rw=randread --bs=4k --size=1G --iodepth=32 \
--ioengine=libaio --direct=1 --runtime=30 --time_based --group_reporting
Absolute IOPS depend heavily on hardware; the useful signal is the gap between two candidates running the same test.
What people use a VPS for
- Outgrowing shared hosting — hitting process or CPU caps, needing Redis, a specific PHP version or custom nginx rules.
- Non-standard stacks — Node.js, Python, Go or Java apps and Docker Compose setups.
- Background work — queue workers, scheduled jobs, bots, CI runners.
- Staging environments — a copy of production you are allowed to break.
- Internal tools — self-hosted Git, file sync, a wiki, monitoring, a company VPN gateway into the office network.
- Mail — possible, but it needs a PTR record, correct SPF, DKIM and DMARC, and a clean IP reputation. Many providers block outbound port 25 until you ask.
VPS vs VPN
The acronyms look alike but name different things. A VPN (virtual private network) is a way of building an encrypted tunnel between devices or networks — for example, letting remote staff reach the office LAN. A VPS is a computer. You can run a VPN server on a VPS, just as you can run a web server on it, but one is a machine and the other is a type of connection.
How to choose a VPS
- Virtualization. KVM if you need Docker, a VPN, another OS or kernel control; containers only for simple Linux workloads.
- Location. Put the server close to your users to cut latency, and check data-residency rules if you store personal data (for example, GDPR obligations for EU users).
- Headroom. For a typical PHP and MySQL site, RAM matters more than cores. Prefer NVMe when there is a database.
- Network. Port speed, traffic caps, IPv6, PTR control and the terms of any DDoS protection.
- Backups. Included or not, how often, and where they are stored. A backup on the same physical host does not survive a disk failure.
- Panel features. Web console, one-click reinstall, a rescue mode that boots from a recovery image.
- Billing. Hourly billing or a trial lets you run the checks above before committing to a year.
A provider-by-provider breakdown with the common fine print is in the best VPS providers compared.
First steps after you get a VPS
You will receive an IP address and a root password, or you will be asked to upload an SSH public key at order time. Linux, macOS and Windows 10/11 all ship an OpenSSH client:
ssh root@203.0.113.10
On Ubuntu or Debian, the first commands are:
apt update && apt upgrade -y
adduser deploy
usermod -aG sudo deploy
Next, switch to key-based login. Generate a key locally with ssh-keygen -t ed25519 and copy it with ssh-copy-id deploy@203.0.113.10 on Linux or macOS; Windows has no ssh-copy-id, so append the contents of the .pub file to ~/.ssh/authorized_keys on the server by hand. The full walkthrough is in setting up SSH key authentication. Once key login works, set these in /etc/ssh/sshd_config:
PasswordAuthentication no
PermitRootLogin no
sudo sshd -t # validate the config
sudo systemctl restart ssh # the unit is called sshd on AlmaLinux and Rocky
Keep your current session open until a second window logs in successfully. Then enable a firewall and automatic security updates:
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable
sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades
Brute-force protection, swap, time zone, backups and monitoring are covered in the 30-minute VPS setup checklist.
How to check a VPS from the outside
- Ping — round-trip time to the server. Before buying, ping the provider's test IP (usually listed on its looking-glass page) to compare locations.
- Port scanner — which ports are reachable from the internet. Expect 22, 80 and 443; an exposed 3306 (MySQL), 5432 (PostgreSQL) or 6379 (Redis) is a misconfiguration to close.
- Reverse IP lookup — which domains still point at the address you were given. IPs are recycled, and a previous tenant's sites may still resolve to yours.
On the server itself, sudo ss -tulpn lists listening sockets and the processes behind them. A service meant for local use only should listen on 127.0.0.1, not 0.0.0.0.
Frequently asked questions
Is a VPS the same as a VDS?
Yes, for practical purposes. Both mean a virtual server; some hosts use the names to separate KVM from container plans, so check the virtualization type rather than the label.
Can I run Windows on a VPS?
On KVM, VMware or Hyper-V, yes, if the host offers a Windows Server image or lets you mount an ISO. The licence is normally billed separately. Containers such as OpenVZ and LXC cannot run Windows.
Do I need Linux skills?
At a basic level: SSH, package updates, a firewall and reading logs. Without them, pick a managed plan or one with a control panel — and keep the system updated regardless.
How many websites can one VPS host?
The limit is resources, not the plan. A single nginx server can serve dozens of small sites; memory and disk run out first, so monitor load and keep critical projects away from experiments.
What happens when a VPS runs out of resources?
When memory is exhausted, the kernel kills processes and the site starts returning 502 or 504 errors. Upgrading is usually a panel action with a reboot; shrinking a disk after enlarging it is rarely possible.
Is a VPS secure?
The hypervisor isolates you from other tenants far better than shared hosting does. Securing the operating system — patches, SSH keys, closed ports — is entirely your job.