Infrastructure tutorials
Production-grade guides for Linux, servers, security and performance. Copy-paste commands, multi-distro support, written by engineers who run this in production.
Browse by topic
Linux
System administration, shell scripting, package management
Hosting & Servers
Web servers, reverse proxies, SSL, domains
Security
Firewalls, hardening, encryption, access control
Performance
Caching, optimization, profiling, load testing
Databases
MySQL, PostgreSQL, Redis, backups, replication
Networking
DNS, load balancing, VPN, TCP/IP, routing
DevOps
CI/CD, Docker, Kubernetes, automation
Monitoring
Logging, alerting, metrics, observability
Most viewed
Install and configure Deno for web development with systemd and reverse proxy
hostingInstall and configure Uptime Kuma for website monitoring with SSL and email alerts
monitoringInstall and configure Caddy web server with automatic HTTPS and reverse proxy
hostingInstall and configure TimescaleDB with PostgreSQL for high-performance time-series data
databasesInstall and configure Ollama for local AI models on Linux servers
devopsRecently published
Configure Ansible Vault integration with HashiCorp Vault for secrets management
devopsImplement Thanos Ruler for distributed alerting and recording rules across Prometheus clusters
monitoringSet up Thanos Query and Compactor for distributed metrics querying
monitoringConfigure Kubernetes network monitoring with Hubble and Cilium for traffic visibility
monitoringConfigure HAProxy with Consul for dynamic service discovery and automatic backend updates
networkingConfigure Ansible Vault integration with HashiCorp Vault for secrets management
Learn how to combine Ansible Vault with HashiCorp Vault using the community.hashi_vault collection, AppRole authentication, and least-privilege policies for production-grade secrets management in playbooks.
Implement Thanos Ruler for distributed alerting and recording rules across Prometheus clusters
Deploy Thanos Ruler to evaluate recording and alerting rules across multiple Prometheus clusters, integrate it with Alertmanager and S3-compatible storage, and run it in HA mode with deduplication.
Configure Kubernetes network monitoring with Hubble and Cilium for traffic visibility
Enable Hubble on Cilium to get real-time eBPF-based flow visibility, deploy Hubble UI and Relay, and integrate flow metrics with Prometheus and Grafana for full Kubernetes network observability.
Configure HAProxy with Consul for dynamic service discovery and automatic backend updates
Build a self-updating load balancer by integrating HAProxy with Consul service discovery, consul-template, and health checks so backends register and deregister automatically without manual reloads.
Implement HAProxy WAF integration with ModSecurity 3 for advanced threat protection
Deploy ModSecurity 3 as a Stream Processing Offload Agent in front of HAProxy to inspect HTTP traffic with the OWASP Core Rule Set. This tutorial covers SPOA compilation, SPOE filter configuration, detection versus blocking modes, and production tuning.
Configure PostgreSQL 17 SSL encryption and certificate-based authentication
Set up a private CA, issue server and client certificates, enforce TLS 1.2+ with strong ciphers, and configure pg_hba.conf for mutual TLS client certificate authentication in PostgreSQL 17.
Set up HAProxy SSL termination with Let's Encrypt certificates
Learn how to terminate SSL/TLS at HAProxy using Let's Encrypt certificates, redirect HTTP to HTTPS, automate renewal with deploy hooks, and harden your cipher suites for production load balancing.
Configure HAProxy with Consul for dynamic service discovery
Learn how to combine HAProxy, Consul and consul-template to build a self-updating load balancer that discovers backends automatically, reacts to health checks, and reloads without downtime.
Configure PostgreSQL 17 connection pooling with PgBouncer for high availability
Deploy PgBouncer in front of PostgreSQL 17 with session, transaction and statement pooling modes, SCRAM-SHA-256 authentication, keepalived-based HA, and Prometheus monitoring for production workloads.
Integrate Jaeger with Istio service mesh for distributed tracing
Learn how to integrate Jaeger with Istio service mesh to get end-to-end distributed tracing across Kubernetes microservices, including sidecar injection, trace sampling, and ingress gateway access to the Jaeger UI.
Configure Consul Connect service mesh monitoring with distributed tracing
Set up comprehensive monitoring for Consul Connect service mesh with Prometheus metrics, Grafana dashboards, Jaeger distributed tracing, and Envoy proxy observability for production-grade service mesh operations.
Configure Kubernetes RBAC with service accounts and cluster roles for secure access control
Learn to implement Kubernetes Role-Based Access Control (RBAC) with service accounts, cluster roles, and role bindings for granular permissions and secure cluster access management.
Don't want to manage this yourself?
We handle infrastructure for businesses that depend on uptime. Fully managed, with one fixed contact who knows your setup.
You get one fixed contact who knows your setup
Rotterdam 15:07 · reachable in a message, no ticket form