What are common practice's for hardening/securing your server?

https://feddit.de/post/11284137

Move services away from known ports and don’t use ports that end with well known port numbers (22,80,443).

Moving ssh from 22 to 2222 or 443 to 10443 does nothing. You have ~65000 ports. Pick something random like 6744 or 2458

Changing ports does nothing except reduced log chatter.
Security through obscurity is not security
It breaks automation. Same thing for changing any default. Change default names, directories and anything else that’s to predictable