14 tutorials · 40 guides
Install Redis 7.0 on Ubuntu 24.04, configure ACL users, secure port 6379, set memory and persistence, and verify backup and restore safely.
Self-host Supabase on Ubuntu 24.04 with the versioned Docker Compose stack, Caddy HTTPS, secure keys, Postgres and Storage backups, restores, and safe updates.
Set up WireGuard on Ubuntu 24.04 for private split-tunnel access. Configure keys, AllowedIPs, UFW, keepalive, private SSH, peers, and verification.
Deploy Vaultwarden on Ubuntu 24.04 with Docker Compose, Caddy HTTPS, locked-down signup/admin access, consistent backups, restores, and safe updates.
Connect two Raff VMs over a private VPC on Ubuntu 24.04. Verify private routing, firewall rules, service access, throughput tests, and safe cleanup.
Set up SSH two-factor authentication on Ubuntu 24.04 with SSH keys plus TOTP, PAM, OpenSSH, safe rollback, recovery codes, and end-to-end login verification.
Set up an SFTP-only user on Ubuntu 24.04 with OpenSSH chroot, internal-sftp, safe directory permissions, forwarding restrictions, and verification.
Install and configure fail2ban on Ubuntu 24.04 for SSH brute-force protection with systemd journal monitoring, safe ban testing, tuning, and rollback.
Generate an SSH key on Ubuntu 24.04 with Ed25519, ssh-keygen, ssh-copy-id, ssh-agent, safe password disabling, troubleshooting, and key rotation.
Install Certbot for Nginx on Ubuntu 24.04, issue a Let's Encrypt SSL certificate, redirect HTTP to HTTPS, test renewal, and troubleshoot common errors.
Build a private remote development VM on Ubuntu 24.04 with code-server and Tailscale Serve, HTTPS, localhost binding, backups, and safe updates.
Harden Ubuntu 24.04 with SSH keys, safe OpenSSH drop-ins, UFW, automatic security updates, AppArmor, access auditing, logging, and recovery checks.
Set up UFW on Ubuntu 24.04 without losing SSH access. Configure IPv4/IPv6 rules, ports, source restrictions, logging, rule order, and Docker caveats.
Install OpenClaw on Ubuntu 24.04 with Telegram pairing, a loopback-only Gateway, secure credentials, SSH-tunneled Control UI, backups, and safe updates.
Plan TLS and application-edge security for cloud workloads: certificates, HSTS, TLS termination, firewalls, WAF, rate limiting, mTLS, headers, and encryption boundaries.
Production serverless operations guide covering triggers, scoped bindings, retries, observability, spend controls, revisions, rollback, and incident recovery.
Use this production VPS checklist to validate SaaS capacity, access, traffic paths, storage, backups, monitoring, restore testing, and scaling decisions before launch.
Run Docker on a cloud VM with a clear production model for security, networking, storage, monitoring, and recovery.
Use this Docker host security checklist to harden production VMs across daemon access, privileges, networking, images, secrets, updates, and recovery.
Learn how to secure serverless APIs with authentication, authorization, CORS, rate limiting, validation, scoped secrets, and safe HTTP Function boundaries.
A practical Kubernetes security baseline for RBAC, ServiceAccounts, Secrets, Pod Security Standards, securityContext, and recurring access reviews.
Learn Kubernetes NetworkPolicy with default-deny, ingress, egress, selectors, DNS rules, examples, rollout checks, and production verification.
Run an access review for cloud servers covering users, SSH keys, RDP, API keys, privileged access, offboarding, private-network reachability, and recovery permissions.
Private vs public admin access for secure remote access across SSH, RDP, VPNs, bastions, break-glass recovery, and Raff VPC.
Private cloud networking for MSPs: design per-client VPCs, client isolation, network segmentation, admin access, peering, VPNs, recovery, and offboarding.
Compare public vs private networks in cloud infrastructure, including private networking, VPCs, NAT, DNS, databases, admin access, and security boundaries.
Secure remote access for MSPs using bastions, VPNs, zero-trust access, client isolation, RDP/SSH controls, technician offboarding, logging, and Raff VPC.
Understand n8n self-hosted automation, when self-hosting makes sense, and how to plan security, backups, scaling, private access, and recovery for production.
Learn cloud access management for small teams: define IAM roles, least privilege, human and machine identities, access reviews, and practical Raff controls.
Learn cloud networking fundamentals across VPCs, routing, NAT, DNS, firewalls, traffic distribution, VPNs, private services, and current Raff networking.
Kubernetes multi-tenancy for MSPs: compare namespace isolation, dedicated worker pools, virtual control planes, and dedicated clusters for security, cost, and operations.
Design VPC architecture for multi-VM applications: private network isolation, CIDR planning, routing, NAT, DNS, service rules, VPN connectivity, and recovery.
Learn Linux commands for cloud servers with a task-based reference for SSH, files, services, logs, networking, security, monitoring, and troubleshooting.
Learn cloud VM patch management for maintenance windows, emergency fixes, deferrals, verification, and rollback planning on production servers.
Learn how small teams use Raff API keys safely for infrastructure automation, CI/CD workflows, inventory checks, backups, and repeatable cloud operations.
Secure S3-compatible buckets with private-by-default access, least-privilege permissions, scoped credentials, presigned URLs, logging, and recovery controls.
Compare shared vs per-client Kubernetes clusters for MSPs across isolation, admin access, blast radius, lifecycle, chargeback, and operations.
Learn how to secure the software supply chain from dependencies and CI/CD to SBOMs, build provenance, secrets, container images, and cloud deployment access.
Use this stale infrastructure and server decommissioning checklist to remove old servers, forgotten keys, abandoned services, DNS, storage, and data safely.
Learn API rate limiting for 429 responses, rate limiting algorithms, token and leaky buckets, API keys, quotas, throttling, and protecting real users.
Compare application logs and audit logs, including event fields, integrity, retention, sensitive-data controls, storage, incident response, and customer-facing audit history.
Learn how DDoS protection and mitigation work for small teams, what to compare in a DDoS protection service, and how to prepare a practical response plan.
Build a practical incident response plan for a small team, with triage, evidence preservation, containment, recovery, communication, and a ready-to-use checklist.
Learn inbound vs outbound cloud firewall rules, least-privilege policy, firewall rule best practices, verification, private networking, and rule lifecycle management.
Compare GitHub-hosted vs self-hosted GitHub Actions runners across cost, security, private networking, ephemeral runners, autoscaling, and operational ownership.
SaaS security and enterprise-readiness checklist for access, backups, monitoring, incidents, evidence, vendors, and customer security reviews.
Compare a bastion host, VPN, and public SSH for secure administration of Linux, Windows RDP, databases, and private cloud servers.
Compare Podman vs Docker for small teams: rootless security, Docker compatibility, Compose vs Quadlet, migration risks, and when to switch runtimes.
Compare IPv4, IPv6, and dual-stack networking for cloud servers, including DNS, firewalls, application binding, monitoring, and migration planning.
Use this VPS setup checklist after deployment to configure updates, SSH access, firewall rules, monitoring, backups, DNS, and recovery in the right order.
Secrets management for cloud apps: compare environment variables, managed secret stores, and Vault-style systems with practical rotation and access guidance.
Learn what self-hosting means, when a self-hosted server makes sense, how SaaS compares, what VM size to start with, and how to plan security and recovery.
Cloud firewall best practices for inbound and outbound rules, SSH/RDP, private services, IPv4/IPv6, VM security, rule reviews, and Raff VPC architecture.
Cloud security fundamentals and best practices for small teams covering identity, server hardening, VPS security, private networking, secrets, backups, monitoring, and incident response.
The tutorials, guides, and comparisons we publish, rounded up in one weekly email. Unsubscribe anytime.
Spin up a Linux or Windows server and follow any tutorial here on real infrastructure. RDP and SSH ready, 14-day money-back guarantee.
Deploy a server