LEVEL 1Shared Setup

Secure the server

Whitelist players and protect the operating system and management tools.

About 8 minEasyReviewed Aug 18, 2026
On this pageFour settings to keepAdd trusted playersProtect the machineNever expose these directly

Four settings to keep#

properties
online-mode=true
white-list=true
enforce-whitelist=true
enable-rcon=false

Online mode verifies player identities. The whitelist limits who can join. Leave RCON off unless you have a specific secured use for it.

Add trusted players#

Use the server console before moving Ubuntu to systemd, Crafty's console on ZimaOS, or an authorized in-game operator command:

minecraft commands
whitelist on
whitelist add PlayerName
whitelist remove PlayerName
whitelist list
op YourMinecraftName
deop PlayerName

Keep operators rare. A normal player usually does not need op.

Protect the machine#

  • Use different long passwords for the router, tunnel and any OS/panel accounts.
  • Keep Windows Remote Desktop, SSH, ZimaOS and Crafty private.
  • Install jars only from official or known project pages.
  • Update one layer at a time and back up first.
  • Remove old operators, whitelist entries, port forwards and tunnels.

Never expose these directly#

  • Windows Remote Desktop or file sharing
  • ZimaOS or Crafty dashboards
  • SSH without deliberate key/firewall protection
  • Docker APIs, databases or NAS file shares

Open or tunnel only the Minecraft game port. A private tool such as Tailscale is a better fit for remote administration.