- Upload install.iso for OpenBSD to Vultr, create a new VM using the ISO. You need the ISO to create full disk encryption. Also this eliminates any potential security issues cloud-init can cause.
- Set a full disk encryption key, set a root password that is strong, set a user that doesn't match anyone's name with a good password.
- Start sshd by default, don't allow root logins.
- Install the entire system to a single / partition (for disk usage reasons)
Each time the VM boots, someone will need to manually enter the encryption key at the prompt.