Ask HN: How do you keep your servers/sites safe from hackers?
This week I expect to receive delivery of a server with which I'll be building a prototype of an OpenStack server whose purpose will be to rent VPS instances to the public. I haven't yet figured out how, but somehow there will be a public facing customer portal providing management access to the rented server instances, and I'm interested in making the security which protects this management panel strong enough to be a selling point when I go live.
I'm a little concerned that by making it a selling point I may be inadvertantly inviting hackers to come attack my site, but its a chance I'm willing to take.
I haven't figured out how OpenStack handles its customer portal yet, but I imagine however it works, it would help to protect it by placing it behind my own customer login system of some sort. I don't know how to code, so I'd have to figure out how to write something to implement this sort of thing- maybe I could crowdsource its development, but even then I would need to know enough about how it would need to be designed so that it would be secure from hackers.
All I know about hacker-proofing is that there's an app that exists called fail2ban that locks out repeated ssh login attempts. I don't know if it could be adapted to work for a site somehow.
How would HN readers make hacker safety a selling point in this case?
Many thanks in advance.
-c