During the initial provisioning of your server, Forge will connect as the root
user over SSH. This is so that Forge is able to add repositories, install dependencies and configure new services, firewalls, and more.
After initially provisioning your server, Forge continues to use root access so that it can manage your server's software, services, and configuration. For example, root access is needed to manage:
We take security very seriously and ensure that we do everything we can to protect customer's data. Below is a brief overview of some of the steps we take to ensure your server's security:
Security updates are automatically applied to your server on a weekly basis. Forge accomplishes this by enabling and configuring Ubuntu's automated security update service that is built in to the operating system.
Forge does not automatically update other software such as PHP or MySQL automatically, as doing so could cause your server to suffer downtime if your application's code is not compatible with the upgrade. However, it is possible to install new versions and patch existing versions of PHP manually via the Forge UI.