preferred
not using root, establishing an user and having to use sudo command instead
lock down iptables, disallow root ssh
what security groups should we really need to open?
pipenv/virtualenv/docker
supervisor gunicorn make sure it has logs nginx
sudo apt-get update && sudo apt-get upgrade