18 tutorials · 33 guides
Deploy Vaultwarden on a Raff Ubuntu 24.04 VM. Covers Docker Compose, Caddy automatic HTTPS, signup lock-down, backups, and end-to-end security checks.
Set up a WireGuard VPN server on a Raff Ubuntu 24.04 VM. Create a VM, generate keys safely, import a client config, and verify the tunnel.
Learn how to install Caddy on Ubuntu 24.04 and configure it as a reverse proxy with automatic HTTPS. Step-by-step tutorial for self-hosting apps on a Raff VM.
Learn how to add MFA to SSH on Ubuntu 24.04 using libpam-google-authenticator and TOTP. Covers PAM config, KbdInteractiveAuthentication, and multi-user rollout.
Learn how to connect two Raff VMs using a private VPC network. Covers network creation, VM attachment, UFW rules, and bandwidth testing with iperf3.
Learn how to restrict users to SFTP-only access on Ubuntu 24.04 using OpenSSH chroot jails. Covers group setup, directory permissions, and sshd_config.
Automate server backups on a Raff Ubuntu 24.04 VM. Covers backup scripts, cron scheduling, rsync off-server sync, retention, monitoring, and restore testing.
Install Caddy web server on a Raff Ubuntu 24.04 VM with automatic HTTPS. This tutorial covers installation, site configuration, automatic Let's Encrypt certificates, reverse proxy setup, and comparison with Nginx.
Install MariaDB 10.11 on Ubuntu 24.04, secure root access, create an app database and user, verify CRUD, and protect port 3306.
Install and configure fail2ban on a Raff Ubuntu 24.04 VM. This step-by-step tutorial covers SSH jail setup, custom ban rules, log monitoring, and integration with UFW.
Set up SSH keys on Ubuntu 24.04 with Ed25519, ssh-copy-id, ssh-agent, safe password disabling, OpenSSH drop-ins, troubleshooting, and key rotation.
Install Redis on Ubuntu 24.04, enable authentication, test cache operations, configure persistence and eviction, and secure port 6379.
Install and configure WireGuard VPN on a Raff Ubuntu 24.04 VM. This step-by-step tutorial covers server setup, client configuration, key generation, and secure tunneling.
Secure Nginx on Ubuntu 24.04 with Let's Encrypt and Certbot. Verify DNS, enable HTTPS redirects, test renewal, and add HSTS safely.
Install MySQL 8.0 on Ubuntu 24.04, keep root on auth_socket, create an app database and user, verify CRUD, and secure port 3306.
Build a remote development VM with code-server and Tailscale on Ubuntu 24.04. Create a secure browser IDE on a Raff VM without exposing it publicly.
Harden an Ubuntu 24.04 server with SSH keys, safe OpenSSH drop-ins, UFW, automatic security updates, service auditing, Fail2Ban, and recovery planning.
Set up UFW on Ubuntu 24.04 without losing SSH access. Configure IPv4 and IPv6 rules, web ports, source restrictions, logging, and Docker caveats.
Learn S3 bucket security for credentials, policies, private access, presigned URLs, logging, recovery, and S3-compatible object storage boundaries.
Compare shared and per-client Kubernetes clusters for MSPs across isolation, admin access, upgrades, blast radius, cost allocation, operations, and service tiers.
Compare bastion, VPN, public administration, and zero-trust access for MSP technicians managing client servers, private networks, and infrastructure.
Design private cloud networking for MSP client isolation with per-client boundaries, management access, firewall policy, CIDR planning, and offboarding controls.
Learn how private cloud networks, CIDR ranges, subnets, routing, and firewall rules isolate multi-VM workloads and databases on Raff.
Use this production VPS checklist to validate SaaS capacity, access, traffic paths, storage, backups, monitoring, restore testing, and scaling decisions before launch.
Learn developer supply chain security risks, from dependencies and CI/CD secrets to cloud server access, with a practical protection framework.
Use this stale infrastructure and server decommissioning checklist to remove old servers, forgotten keys, abandoned services, DNS, storage, and data safely.
Understand API rate limiting with a decision framework for fair usage, abuse prevention, endpoint protection, 429 responses, and real-user experience.
Run a user access review across SSH keys, Linux and Windows admins, RDP users, API keys, service accounts, permissions, exposure, and offboarding.
Compare application logs and audit logs, including event fields, integrity, retention, sensitive-data controls, storage, incident response, and customer-facing audit history.
Learn DDoS protection for small teams with a risk framework for exposure, traffic layers, response planning, recovery, and cloud server controls.
Build a small-team incident response plan covering triage, evidence, containment, recovery, communication, validation, and post-incident review.
Learn cloud VM patch management with a risk matrix for maintenance windows, emergency fixes, deferrals, and rollback planning for production server teams.
Understand when small teams should use Windows VPS hosting for RDP, business software, IIS, MSSQL, and remote access, with sizing and licensing guidance.
Learn how Restic, Borg, and Rsync compare for cloud server backups. Understand encryption, deduplication, restore speed, retention, and Raff storage options.
Decide when public SSH or RDP is acceptable and when production infrastructure should use private, restricted, or identity-based admin access.
Understand inbound and outbound firewall rules, the least privilege principle, and how to design a firewall policy for your Raff cloud infrastructure. A practical decision framework for sysadmins and DevOps teams.
Learn MSP backup and disaster recovery strategy by comparing retention, testing, and recovery planning. Build a client-ready data protection baseline.
Use this SaaS infrastructure checklist to prepare access, environments, secrets, backups, monitoring, incident response, and evidence before enterprise onboarding.
Compare GitHub-hosted vs self-hosted runners across security, cost, private networking, autoscaling, ephemeral execution, and operational control.
Learn how MSPs should design multi-tenant Kubernetes environments with namespaces, RBAC, quotas, network policies, node isolation, cost allocation, and client-aware cluster models.
Compare Podman vs Docker across rootless security, Compose compatibility, systemd integration, networking, storage, and migration risk.
Compare public SSH, bastion hosts, and VPN access models for cloud servers, private networks, databases, Windows RDP, and small-team infrastructure.
Use this VPS setup checklist after deployment to configure updates, SSH access, firewall rules, monitoring, backups, DNS, and recovery in the right order.
Compare IPv4, IPv6, and dual-stack networking for cloud servers, including DNS, firewalls, application binding, monitoring, and migration planning.
Learn essential Linux commands for cloud servers: SSH, files, users, permissions, UFW, systemctl, logs, disk, memory, networking, troubleshooting, and safe production workflows.
Compare environment variables, vaults, and managed secret stores for cloud apps. Learn when each fits, how to rotate secrets, reduce exposure, and avoid secret sprawl.
Compare cloud-init, custom images, and one-click apps for VM provisioning. Learn when to use each model and how to combine them safely.
Understand public vs private cloud traffic, NAT, DNS, firewall boundaries, administrative access, and private-network architecture on Raff.
Decide when self-hosting makes sense, compare SaaS, managed, cloud VM, and local infrastructure, and plan security, backups, ownership, and recovery.
Learn cloud firewall best practices for inbound, outbound, administrative, private, IPv4, and IPv6 traffic without overexposing services.
Learn the cloud security fundamentals small teams need across identity, network exposure, server hardening, secrets, recovery, monitoring, and incident response.
The tutorials, guides, and comparisons we publish, rounded up in one weekly email. Unsubscribe anytime.
Spin up a Linux or Windows server and follow any tutorial here on real infrastructure. RDP and SSH ready, 14-day money-back guarantee.
Deploy a server