Infrastructure tutorials
Production-grade guides for Linux, servers, security and performance. Copy-paste commands, multi-distro support, written by engineers who run this in production.
Browse by topic
Linux
System administration, shell scripting, package management
Hosting & Servers
Web servers, reverse proxies, SSL, domains
Security
Firewalls, hardening, encryption, access control
Performance
Caching, optimization, profiling, load testing
Databases
MySQL, PostgreSQL, Redis, backups, replication
Networking
DNS, load balancing, VPN, TCP/IP, routing
DevOps
CI/CD, Docker, Kubernetes, automation
Monitoring
Logging, alerting, metrics, observability
Most viewed
Install and configure Deno for web development with systemd and reverse proxy
hostingInstall and configure Uptime Kuma for website monitoring with SSL and email alerts
monitoringInstall and configure Caddy web server with automatic HTTPS and reverse proxy
hostingFix apt update E: Repository no longer has a Release file
linuxInstall and configure TimescaleDB with PostgreSQL for high-performance time-series data
databasesRecently published
Configure Logstash 8 security pipelines with threat intelligence enrichment
monitoringConfigure Ansible Vault integration with HashiCorp Vault for secrets management
devopsImplement Thanos Ruler for distributed alerting and recording rules across Prometheus clusters
monitoringSet up Thanos Query and Compactor for distributed metrics querying
monitoringConfigure Kubernetes network monitoring with Hubble and Cilium for traffic visibility
monitoringImplement Thanos Ruler for distributed alerting and recording rules across Prometheus clusters
Deploy Thanos Ruler to evaluate recording and alerting rules across multiple Prometheus clusters, integrate it with Alertmanager and S3-compatible storage, and run it in HA mode with deduplication.
Set up Thanos Query and Compactor for distributed metrics querying
Deploy Thanos Sidecar, Query, and Compactor to unify multiple Prometheus instances into a single global query view with long-term S3-backed storage. Covers deduplication, TLS, and production troubleshooting.
Configure HAProxy with Consul for dynamic service discovery and automatic backend updates
Build a self-updating load balancer by integrating HAProxy with Consul service discovery, consul-template, and health checks so backends register and deregister automatically without manual reloads.
Implement HAProxy WAF integration with ModSecurity 3 for advanced threat protection
Deploy ModSecurity 3 as a Stream Processing Offload Agent in front of HAProxy to inspect HTTP traffic with the OWASP Core Rule Set. This tutorial covers SPOA compilation, SPOE filter configuration, detection versus blocking modes, and production tuning.
Set up HAProxy SSL termination with Let's Encrypt certificates
Learn how to terminate SSL/TLS at HAProxy using Let's Encrypt certificates, redirect HTTP to HTTPS, automate renewal with deploy hooks, and harden your cipher suites for production load balancing.
Configure HAProxy with Consul for dynamic service discovery
Learn how to combine HAProxy, Consul and consul-template to build a self-updating load balancer that discovers backends automatically, reacts to health checks, and reloads without downtime.
Configure Kubernetes secrets management with External Secrets Operator and HashiCorp Vault
Learn how to deploy External Secrets Operator on Kubernetes, integrate it with HashiCorp Vault using the Kubernetes auth method, and sync secrets via SecretStore and ClusterSecretStore resources with production-grade RBAC and monitoring.
Configure Jaeger authentication with OAuth2 and RBAC for enterprise security
Set up enterprise-grade authentication for Jaeger distributed tracing using OAuth2 with Keycloak integration and role-based access control policies for secure production deployments.
Configure NTP monitoring with Grafana dashboards and Prometheus alerting
Set up comprehensive time synchronization monitoring using chrony, Prometheus node exporter, and custom Grafana dashboards with alerting for time drift and NTP service failures.
Configure advanced Jaeger sampling strategies for high-traffic environments
Configure probabilistic, adaptive, and remote sampling strategies for Jaeger distributed tracing to optimize performance and storage costs in high-throughput production environments while maintaining observability.
Implement Kubernetes secrets management with HashiCorp Vault integration
Set up HashiCorp Vault with Kubernetes to dynamically inject secrets into pods using the Vault Secrets Operator. This tutorial covers authentication configuration, operator deployment, and automated secret injection with annotations.
Integrate ClamAV cluster with file upload APIs for scalable malware scanning
Set up a clustered ClamAV deployment with REST API endpoints for automated malware scanning of file uploads. Configure load balancing, authentication, and monitoring for high-availability antivirus scanning in production environments.
Don't want to manage this yourself?
We handle infrastructure for businesses that depend on uptime. Fully managed, with one fixed contact who knows your setup.
You get one fixed contact who knows your setup
At their desk in Rotterdam 17:29 · reachable in a message, no ticket form