SSH is usually the one service on a server that the whole internet can reach, and automated scanners try it within minutes of a machine coming online. A few settings remove most of the risk, but each one can also lock you out if applied carelessly.
Password guessing is how most SSH compromises start. Turning off PasswordAuthentication leaves only public-key login, which cannot be guessed. Before you do, confirm in a second terminal that your key actually works, because turning passwords off with no working key leaves no way in.
PubkeyAuthentication yes
PasswordAuthentication no
AuthenticationMethods publickey
PermitRootLogin nosshd uses the first value it reads for each setting, and it reads files in /etc/ssh/sshd_config.d in alphabetical order. A cloud image often ships 50-cloud-init.conf containing PasswordAuthentication yes, so a hardening file named 99-hardening.conf is silently ignored. Name yours 00-hardening.conf, and make sure the Include line sits near the top of sshd_config, not the bottom.
# /etc/ssh/sshd_config.d/00-hardening.conf
PasswordAuthentication noCheck the syntax with sshd -t, reload instead of restarting so that your current session survives, then open a new connection in a second terminal and confirm it works before closing the first. If it fails, the old session is still there to undo the change. Changing the port needs the firewall opened for it before the reload.
sudo sshd -t
sudo systemctl reload ssh
# in a second terminal:
ssh -p 22 you@your-serverMaxAuthTries 3 cuts the number of guesses per connection, AllowUsers names the only accounts that may log in, and a ClientAliveInterval drops dead sessions. Forwarding of X11 and TCP are off unless you use them. Restricting key exchange, ciphers and MACs to modern ones helps, but stops very old clients from connecting.
Open the SSH hardening generator
It reduces noise in your logs because most scanners try port 22, but it does not stop a determined attacker, who can scan every port. Treat it as housekeeping, not as a security control.
Reload re-reads the configuration while leaving existing connections alone. Restart stops sshd and starts it again, which can drop your session if the new configuration has a problem.
Run sudo sshd -T. It prints the effective value of every setting after all files are read, so you can see whether your drop-in or a distribution file won.