Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Secure the Droplet according to what it actually does in the streaming workflow. If it sends video directly to YouTube, it generally needs outbound connectivity, not a public inbound video port. If it receives video from another encoder as a relay, expose only the relay’s configured port and only to the extent the workflow requires. In either case, use key-based SSH with a non-root administrator, layer DigitalOcean Cloud Firewall rules with Ubuntu’s host firewall, keep security updates flowing, and protect the YouTube stream key.

First identify the Droplet’s role and recovery path

The title does not establish whether the Droplet is an encoder, a relay, or a host for control and automation. That distinction determines whether any inbound video port is needed. YouTube’s official RTMPS guidance describes an encoder connecting to YouTube; it does not prescribe inbound ports for every server used in a streaming setup.

  • Direct encoder: the streaming process runs on the Droplet and sends video out to YouTube. Investigate the outbound DNS and RTMPS connectivity it needs; do not open an inbound video port just because the server streams.
  • Relay: another machine sends video to a service listening on the Droplet. Identify that service’s actual protocol, port, and source machines before writing firewall rules. Keep the inbound port closed until the relay is configured and ready to test.
  • Control or automation host: the Droplet may manage a workflow without receiving video. Allow only the management and application access that role actually needs.

Before changing SSH or firewall settings, note the Ubuntu release, sudo administrator, SSH port, and video path. Confirm that a backup exists and that you know how to recover access. DigitalOcean describes its backups as system-level disk images available on daily or weekly schedules, with potentially more frequent schedules; a backup is useful for recreating or reverting a Droplet, but does not replace configuration management or a tested restore procedure. See DigitalOcean’s recommended Droplet setup.

DigitalOcean’s Recovery Console provides out-of-band access when network settings or SSH prevent normal login. Keep it as a recovery route, not the routine way you administer the server; use SSH or the regular Droplet Console for ordinary management.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Harden SSH before restricting access

Use a named sudo account and public-key authentication

Administer the Droplet through a named, non-root account with sudo privileges. Configure public-key SSH access and protect the private key; Ubuntu recommends Ed25519 for new keys, with RSA 4096 as an alternative in its guidance. Ubuntu also documents FIDO/U2F hardware authentication as an optional additional factor. DigitalOcean’s setup guidance likewise recommends SSH keys, a sudo non-root user, and disabling password-based root login.

Disable password-based root access only after confirming that the intended account can connect using its key and can run sudo. Ubuntu notes that SSH settings may be in /etc/ssh/sshd_config or included files under /etc/ssh/sshd_config.d/. Check the effective configuration and validate edits using the OpenSSH tools available on the installed system, rather than assuming one file contains every active setting. Refer to the Ubuntu OpenSSH guide.

Test a second session before closing the first

  1. Keep your existing SSH session open while testing the new configuration.
  2. Start a second session using the intended administrator account and key.
  3. Confirm that the account can run a sudo command successfully.
  4. Only then close the original session or proceed with more restrictive SSH and firewall changes.

Maintain the recovery route described above while making changes. For long administrative tasks that need to survive a dropped connection, Ubuntu’s SSH guidance recommends a terminal multiplexer such as tmux or screen. A multiplexer helps preserve a working session; it is not an authentication control.

Which ports should you open for YouTube streaming?

There is no universal inbound video-port list for a YouTube streaming Droplet. Decide based on whether the Droplet accepts connections from another machine. YouTube’s RTMPS instructions concern sending an encoder’s stream to YouTube, not receiving an incoming stream on your server.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Direct-to-YouTube from the Droplet: do not add a public inbound video rule unless a separate service requires it. Check outbound DNS and RTMPS connectivity for the encoder you use.
  • Video pushed from another encoder to a Droplet relay: confirm the relay’s configured listening protocol and port. Allow that inbound traffic only after the service is configured and tested; restrict the permitted source addresses when feasible.
  • SSH administration: permit the actual SSH management port and, where practical, restrict its source to trusted addresses. The SSH port is deployment-specific; do not assume it is the default.

Keep IPv4 and IPv6 policy consistent if IPv6 is enabled. DigitalOcean recommends beginning with inbound SSH only and broad outbound access, since ordinary services depend on outbound connectivity. Add inbound access only for services the Droplet is meant to provide.

Layer DigitalOcean Cloud Firewall and Ubuntu ufw

These controls work at different layers and complement one another; neither should be treated as a substitute for the other.

Control Where it applies Practical use
DigitalOcean Cloud Firewall Provider network; attached to individual Droplets or by tag Define explicit allowed traffic at the provider layer. It is stateful and blocks traffic unless a rule permits it.
Ubuntu ufw On the Droplet itself Apply host-level firewall policy for the machine. Ubuntu’s default firewall interface is ufw, which begins disabled.

See the DigitalOcean Cloud Firewall documentation and Ubuntu ufw documentation. Decide which layer controls each exposure and keep the rules understandable and documented.

  1. In the DigitalOcean control panel, create or review a Cloud Firewall for the Droplet. Start with only the SSH management rule needed for your access path; retain broad outbound access unless your workflow has a specific reason to restrict it.
  2. Restrict SSH source addresses to trusted addresses when they are stable and your access requirements allow it. Apply compatible IPv4 and IPv6 rules if both are in use.
  3. On Ubuntu, verify that the intended SSH rule is present before enabling ufw. Since ufw starts disabled, enabling it with an incorrect rule can cut off remote access.
  4. After changes, inspect the host firewall with sudo ufw status verbose and sudo ufw status numbered. Confirm that the actual SSH and application rules match the intended policy.
  5. Add a relay port only if the Droplet receives a stream, and limit its sources where feasible. Do not create a public inbound video rule for a direct outbound encoder without a separate requirement.

Keep Ubuntu patched without surprising the stream

Ubuntu documents unattended-upgrades as installed by default on supported modern installations and security updates as running daily by default. Those defaults can differ on customized images, so check the installed release and configuration. Review /var/log/unattended-upgrades and decide how you will be notified about pending reboots. Ubuntu’s automatic updates documentation explains the configuration, including update origins and whether an automatic reboot is allowed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not turn off security updates merely to avoid an interruption. Instead, make maintenance observable and plan reboots or service restarts for a time when interrupting a live session is acceptable. A kernel or service restart can interrupt streaming. DigitalOcean’s recommended setup includes its metrics agent; monitor CPU, disk, bandwidth, and service health so you can investigate resource exhaustion or an encoder/relay fault as well as security problems.

Ubuntu recommends an LTS release for server deployments. Its release-upgrade guidance states that LTS releases receive five years of standard support and security updates, while interim releases are supported for nine months. These are Ubuntu release-policy durations, not a guarantee that a particular Droplet is patched: the machine must be on an eligible release and configured appropriately. Check Ubuntu’s release-upgrade guidance for the applicable release details.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use RTMPS and keep the YouTube stream key secret

YouTube Help says, “You can stream to YouTube Live with RTMPS, a secure extension to the popular RTMP streaming video protocol.” It explains that RTMPS carries RTMP over TLS/SSL and instructs creators to copy the stream key from Live Control Room into the encoder. Follow YouTube’s current RTMPS instructions and the documentation for your specific encoder.

  • Keep the stream key out of public repositories, screenshots, logs, support tickets, and shell history.
  • Use the encoder’s secret-management method where available. If a local configuration file is unavoidable, restrict its file permissions.
  • If the key is exposed, rotate it through YouTube and update the encoder that uses it.
  • If your encoder lacks an RTMPS preset, check its current documentation for server URL and protocol support. Do not assume plain RTMP is encrypted; verify that the encoder actually supports RTMPS.

Troubleshoot common access and streaming failures

Symptom Likely cause What to check
SSH stops working after a firewall change The SSH rule is missing, uses the wrong port, or excludes your current source address. Use a still-open session or DigitalOcean Recovery Console to inspect the effective SSH configuration and firewall rules. Correct the management rule before tightening access again.
SSH key login fails after password login was disabled The key, account, permissions, or effective SSH settings are wrong. Test from a second session before closing a working one; confirm the intended account and key are configured and that included SSH snippets have been checked.
The encoder cannot reach YouTube from the Droplet Outbound DNS or RTMPS connectivity may be blocked, or the encoder may not support the configured secure protocol. Check outbound policy and the encoder’s current RTMPS settings. Do not try to solve an outbound connection problem by opening an unrelated inbound port.
A remote encoder cannot send video to a relay The relay may not be listening, or the relevant inbound rule may be absent or too restrictive. Confirm the relay’s configured protocol and listening port, then compare its source restrictions with the Cloud Firewall and ufw rules. Expose only the required service.
The stream ends during maintenance A reboot, kernel update, or service restart interrupted the active process. Review update logs and service health, then schedule disruptive maintenance deliberately and ensure you have a recovery procedure.
Unexpected stream activity appears The stream key may have been exposed or used from an unexpected location. Rotate the key in YouTube, update the authorized encoder, and remove the exposed copy from repositories or other accessible locations.

Or let it run in the cloud

If your goal is to keep uploaded videos looping on a YouTube channel rather than operate a Droplet-based encoder or relay, StreamNeo is a cloud option: upload a recording or build a playlist, add your YouTube stream key, and go live. Nothing has to stay on at home. Each slot streams the uploaded quality up to 4K 60fps at one flat price per slot, with automatic recovery if YouTube drops the stream. The first day is free with no card; the Monthly price is $9.99 per month. This service plays uploaded videos and streams to YouTube; it does not stream from a camera.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start your free StreamNeo day.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.