LEVEL 1Shared Setup
Secure the server
Whitelist players and protect the operating system and management tools.
About 8 minEasyReviewed Aug 18, 2026
Four settings to keep#
properties
online-mode=true
white-list=true
enforce-whitelist=true
enable-rcon=falseOnline mode verifies player identities. The whitelist limits who can join. Leave RCON off unless you have a specific secured use for it.
Add trusted players#
Use the server console before moving Ubuntu to systemd, Crafty's console on ZimaOS, or an authorized in-game operator command:
minecraft commands
whitelist on
whitelist add PlayerName
whitelist remove PlayerName
whitelist list
op YourMinecraftName
deop PlayerNameKeep operators rare. A normal player usually does not need op.
Protect the machine#
- Use different long passwords for the router, tunnel and any OS/panel accounts.
- Keep Windows Remote Desktop, SSH, ZimaOS and Crafty private.
- Install jars only from official or known project pages.
- Update one layer at a time and back up first.
- Remove old operators, whitelist entries, port forwards and tunnels.
Never expose these directly#
- Windows Remote Desktop or file sharing
- ZimaOS or Crafty dashboards
- SSH without deliberate key/firewall protection
- Docker APIs, databases or NAS file shares
Open or tunnel only the Minecraft game port. A private tool such as Tailscale is a better fit for remote administration.