Infrastructure tutorials
Production-grade guides for Linux, servers, security and performance. Copy-paste commands, multi-distro support, written by engineers who run this in production.
Browse by topic
Linux
System administration, shell scripting, package management
Hosting & Servers
Web servers, reverse proxies, SSL, domains
Security
Firewalls, hardening, encryption, access control
Performance
Caching, optimization, profiling, load testing
Databases
MySQL, PostgreSQL, Redis, backups, replication
Networking
DNS, load balancing, VPN, TCP/IP, routing
DevOps
CI/CD, Docker, Kubernetes, automation
Monitoring
Logging, alerting, metrics, observability
Most viewed
Install and configure Deno for web development with systemd and reverse proxy
hostingInstall and configure Uptime Kuma for website monitoring with SSL and email alerts
monitoringInstall and configure Caddy web server with automatic HTTPS and reverse proxy
hostingInstall and configure TimescaleDB with PostgreSQL for high-performance time-series data
databasesInstall and configure Ollama for local AI models on Linux servers
devopsRecently published
Configure Logstash 8 security pipelines with threat intelligence enrichment
monitoringConfigure Ansible Vault integration with HashiCorp Vault for secrets management
devopsImplement Thanos Ruler for distributed alerting and recording rules across Prometheus clusters
monitoringSet up Thanos Query and Compactor for distributed metrics querying
monitoringConfigure Kubernetes network monitoring with Hubble and Cilium for traffic visibility
monitoringConfigure Ansible Vault integration with HashiCorp Vault for secrets management
Learn how to combine Ansible Vault with HashiCorp Vault using the community.hashi_vault collection, AppRole authentication, and least-privilege policies for production-grade secrets management in playbooks.
Implement HAProxy WAF integration with ModSecurity 3 for advanced threat protection
Deploy ModSecurity 3 as a Stream Processing Offload Agent in front of HAProxy to inspect HTTP traffic with the OWASP Core Rule Set. This tutorial covers SPOA compilation, SPOE filter configuration, detection versus blocking modes, and production tuning.
Configure PostgreSQL 17 SSL encryption and certificate-based authentication
Set up a private CA, issue server and client certificates, enforce TLS 1.2+ with strong ciphers, and configure pg_hba.conf for mutual TLS client certificate authentication in PostgreSQL 17.
Configure Kubernetes secrets management with External Secrets Operator and HashiCorp Vault
Learn how to deploy External Secrets Operator on Kubernetes, integrate it with HashiCorp Vault using the Kubernetes auth method, and sync secrets via SecretStore and ClusterSecretStore resources with production-grade RBAC and monitoring.
Configure Kubernetes RBAC with service accounts and cluster roles for secure access control
Learn to implement Kubernetes Role-Based Access Control (RBAC) with service accounts, cluster roles, and role bindings for granular permissions and secure cluster access management.
Implement Kubernetes security scanning with Falco and OPA Gatekeeper for runtime protection
Set up comprehensive Kubernetes security with Falco for runtime threat detection and OPA Gatekeeper for admission control policy enforcement. This tutorial covers installation, configuration, and custom security policies.
Configure Jaeger with Elasticsearch backend security and encryption
Set up secure communication between Jaeger and Elasticsearch using TLS encryption, authentication, and production-grade security hardening for distributed tracing infrastructure.
Configure ArgoCD Image Updater for automated container deployments
Set up ArgoCD Image Updater to automatically detect and deploy new container image versions in your GitOps workflow. Includes Git repository integration, webhook configuration, and monitoring setup.
Implement backup encryption key rotation and secure management with GPG and automated scripts
Build a production-grade backup encryption system with automated GPG key rotation, secure key distribution, and monitoring. Learn to implement enterprise-level key management policies with systemd timers and secure storage practices.
Configure Istio security policies with external authorization services integration
Set up comprehensive Istio security policies with external authorization services, JWT validation, and RBAC integration for enterprise-grade service mesh security and compliance.
Implement Docker network security with custom bridge networks and container isolation
Secure your Docker deployments by creating isolated custom bridge networks, implementing container segmentation, and configuring network access controls to prevent unauthorized communication between containers.
Set up container runtime security with Falco and Sysdig for threat detection
Configure Falco for runtime security monitoring and Sysdig Agent for container visibility to detect threats in Kubernetes environments. Implement behavioral analysis, custom security rules, and threat detection policies for production container workloads.
Don't want to manage this yourself?
We handle infrastructure for businesses that depend on uptime. Fully managed, with one fixed contact who knows your setup.
You get one fixed contact who knows your setup
Rotterdam 09:49 · reachable in a message, no ticket form