Infrastructure tutorials

Production-grade guides for Linux, servers, security and performance. Copy-paste commands, multi-distro support, written by engineers who run this in production.

monitoring Advanced

Configure Logstash 8 security pipelines with threat intelligence enrichment

Build a production Logstash 8 pipeline that ingests firewall, IDS and syslog data, enriches events with MISP, AlienVault OTX and AbuseIPDB threat intel, and ships hardened IOC-enriched events to Elasticsearch.

75 min 4 distros 2 views
devops Advanced

Configure Ansible Vault integration with HashiCorp Vault for secrets management

Learn how to combine Ansible Vault with HashiCorp Vault using the community.hashi_vault collection, AppRole authentication, and least-privilege policies for production-grade secrets management in playbooks.

45 min 4 distros 39 views
monitoring Advanced

Implement Thanos Ruler for distributed alerting and recording rules across Prometheus clusters

Deploy Thanos Ruler to evaluate recording and alerting rules across multiple Prometheus clusters, integrate it with Alertmanager and S3-compatible storage, and run it in HA mode with deduplication.

60 min 4 distros 87 views
monitoring Advanced

Configure Kubernetes network monitoring with Hubble and Cilium for traffic visibility

Enable Hubble on Cilium to get real-time eBPF-based flow visibility, deploy Hubble UI and Relay, and integrate flow metrics with Prometheus and Grafana for full Kubernetes network observability.

75 min 4 distros 215 views
networking Advanced

Configure HAProxy with Consul for dynamic service discovery and automatic backend updates

Build a self-updating load balancer by integrating HAProxy with Consul service discovery, consul-template, and health checks so backends register and deregister automatically without manual reloads.

75 min 4 distros 226 views
security Advanced

Implement HAProxy WAF integration with ModSecurity 3 for advanced threat protection

Deploy ModSecurity 3 as a Stream Processing Offload Agent in front of HAProxy to inspect HTTP traffic with the OWASP Core Rule Set. This tutorial covers SPOA compilation, SPOE filter configuration, detection versus blocking modes, and production tuning.

75 min 4 distros 253 views
databases Advanced

Configure PostgreSQL 17 SSL encryption and certificate-based authentication

Set up a private CA, issue server and client certificates, enforce TLS 1.2+ with strong ciphers, and configure pg_hba.conf for mutual TLS client certificate authentication in PostgreSQL 17.

45 min 4 distros 281 views
networking Intermediate

Set up HAProxy SSL termination with Let's Encrypt certificates

Learn how to terminate SSL/TLS at HAProxy using Let's Encrypt certificates, redirect HTTP to HTTPS, automate renewal with deploy hooks, and harden your cipher suites for production load balancing.

35 min 4 distros 486 views
networking Advanced

Configure HAProxy with Consul for dynamic service discovery

Learn how to combine HAProxy, Consul and consul-template to build a self-updating load balancer that discovers backends automatically, reacts to health checks, and reloads without downtime.

50 min 4 distros 436 views
databases Intermediate

Configure PostgreSQL 17 connection pooling with PgBouncer for high availability

Deploy PgBouncer in front of PostgreSQL 17 with session, transaction and statement pooling modes, SCRAM-SHA-256 authentication, keepalived-based HA, and Prometheus monitoring for production workloads.

45 min 4 distros 399 views
devops Advanced

Integrate Jaeger with Istio service mesh for distributed tracing

Learn how to integrate Jaeger with Istio service mesh to get end-to-end distributed tracing across Kubernetes microservices, including sidecar injection, trace sampling, and ingress gateway access to the Jaeger UI.

60 min 4 distros 444 views
devops Intermediate

Configure Kubernetes RBAC with service accounts and cluster roles for secure access control

Learn to implement Kubernetes Role-Based Access Control (RBAC) with service accounts, cluster roles, and role bindings for granular permissions and secure cluster access management.

25 min 4 distros 1,659 views

Don't want to manage this yourself?

We handle infrastructure for businesses that depend on uptime. Fully managed, with one fixed contact who knows your setup.

You get one fixed contact who knows your setup

At their desk in Rotterdam 17:15 · reachable in a message, no ticket form