Which server ports needs to remain open?

Only SSH port (by default 22 or your custom SSH port provided) and HTTP/HTTPS (80/443).