Scale up as you grow — whether you're running one virtual machine or ten thousand.

From GPU-powered inference and Kubernetes to managed databases and storage, get everything you need to build, scale, and deploy intelligent applications.

This textbox defaults to using Markdown to format your answer.
You can type !ref in this text area to quickly search our full set of tutorials, documentation & marketplace offerings and insert the link!
These answers are provided by our Community. If you find them useful, show some love by clicking the heart. If you run into issues leave a comment, or add your own answer to help others.
Hello friend!
I think you will find that preference is really the key to this part for most people. I always tell people that security and convenience, as well as recovery effort in relation to that, should always be relative to the value of what is behind it. I’ll give a mildly humorous example just to highlight extremes on either side of it:
Too little security is Facebook messaging your private key to your best friend for backup, for a server that houses personal information about 100,000 of your customers. Too much security is hiring a team of guards to protect a flash drive with your private key on it, for a server that houses a blog you haven’t gotten around to writing on yet.
That’s going to the extreme on either side to highlight that the best practice really is somewhat relative. If you reversed the two, it almost wouldn’t seem crazy anymore. You have to decide for the value of your situation what is going to be the proper amount of security and convenience for your needs. Maybe that’s storing a flash drive in a lock box somewhere, maybe just that external drive. Maybe it’s having a key for every machine or sharing one between your machines (though bonus of multiple is that you can kill one key if a machine is stolen).
I know that wasn’t terribly informative but I think you already have a great mind for this and you are already thinking on the right path. I believe that you will make the best decisions for your situation on this :)
Kind Regards, Jarland
See the Droplet Resources page, How to Regain Access to Droplets using the DigitalOcean Droplet Console.
The Access tab on your Droplet control panel offers the Reset Root Password button to create a password for the root user on your FreeBSD or Linux VM.
Then use the Launch Console button. This starts a server-local connection, as if you connected a keyboard & mouse to the server box. Then you view the session remotely via a VNC session within the web browser. Use your root password to take control of your machine again.