Skip to content

Building an Application Server

Configuring the Servre

Securing the Server

The first thing to do is to secure the server. It's good to do this first so you don't forget to come back to it once your server is actually hosting a site.

Additionally, a mistake here comes with a risk of locking yourself out. Do this early so that if you need to just delete the server and restart you can easily do so without losing work.

Creating a New User

Disable root SSH and password login.

Configure UFW

Enable fail2ban

Enable unattended-upgrades

General Rules

  • Avoid exposing anything publicly, typically no more ports should be opened.
  • Be aware docker will punch holes in the firewall if not bound to 127.0.0.1, we'll revisit that later.
  • Things are pretty secure as they are, but you may want to move port 22 to prevent automated attacks against the well-known SSH port. (TODO)

Running Applications

There are two common paths to handling long-running applications on the server. systemd is already running on the server and manages existing long-running processes. It is possible to run your own application as a systemd process, and install packages like caddy, postgres, redis, etc. using apt which will give them systemd processes as well.

For our purposes however we'll be using docker to run containerized services.

Installing Docker

A Basic docker-compose

caddy

  • automatic SSH, short config
  • reverse proxy
  • alternatives: traefik, nginx

gunicorn

  • what it does
  • workers, timeouts, etc.

postgres

secrets

  • never commit to git
  • .env files, chmod 600, --env-file
  • sops/age
  • if it leaks: rotate/disclose

DNS and HTTPS

  • buying a domain
  • A/AAAA
  • wildcards
  • dig +short

Deploying Updates

  • one command
  • docker
  • just commands

Maintaining the Server

Security Updates

  • unattended-upgrades
  • manual reboots on kernel upgrades
  • docker system prune
  • apt autoremove

Backups

  • what to backup
  • provider snapshots
  • database dumps
  • restic backups
  • 3-2-1
  • backup encryption key storage
  • testing a restore

Monitoring

  • simple uptime check
  • monitoring cron jobs
  • disk space
  • logs