Linux servers, set up properly and kept running
You inherited a server, or you set one up in a hurry two years ago and it has been running ever since. It works. Nobody is quite sure what is on it, whether the backups restore, or what happens if it stops.
That is a very normal position to be in, and it is fixable in a couple of days rather than a couple of months.
What you get
- Provisioning and hardening: firewall, SSH key-only access, fail2ban, audited against Lynis
- nginx, TLS certificates that renew themselves, and deployments that can be rolled back
- Encrypted off-site backups that are tested by restoring them, not assumed
- Documentation written so somebody who is not me can pick it up
Who it's for
Anyone running a VPS or a small server estate who inherited it, is not sure what state it is in, or is currently the only person who knows how it works.
How it's priced
One-off hardening and setup at a fixed price, or a monthly arrangement if you want somebody on the end of the phone. Priced per server, not per hour.
Case study
Systems I manage
Every script backs up what it touches
The problem. Hardening scripts are the ones you least want to run on a live box on a Thursday afternoon, which means they sit unrun and the machine stays unhardened. The risk is not the script. It is the hesitation.
What I did.
- Made every script copy what it is about to change to a timestamped backup first, so a bad change is one move from undone
- Made every script safe to run twice, because you will run it twice and so will somebody else
- Kept the working session open and tested changes from a second one, so a lockout is always recoverable
Outcome. Changes get made on live servers in working hours instead of waiting for a weekend that never comes. The confidence is the deliverable; the backup file is how you buy it.
Questions people ask
- What does hardening actually involve?
- Cutting SSH back to key-only access, a host firewall that denies by default, fail2ban on anything exposed, removing services that are listening for no reason, and then auditing the result against Lynis rather than assuming it worked. I verify from outside the box, not by reading the config back.
- Will you lock me out of my own server?
- No. Every change is made with a working session open and tested from a second one, so there is always a way back. Every script I write backs up what it is about to change to a timestamped file first.
- Do you offer ongoing support?
- Yes, monthly, priced per server. That covers patching, monitoring, and being the person who picks up when something breaks. If you only want the one-off setup, that is fine too.
- Do you test the backups?
- Yes, by restoring them. A backup nobody has restored is a belief, not a backup. That is the single most common thing I find not working.
Talk about your project
Tell me what you're trying to do and roughly what it's worth to you. The first call is free, half an hour, and you get a straight answer about whether I'm the right person.
That's with me.
I read these myself and reply within a working day, usually sooner. If it's urgent, ring 07853 610930.
The other two things I do
Software builds
Web apps, client portals and internal tools. Built, deployed, and running on infrastructure I look after.
Security audits
Find out what is actually exposed, with the evidence attached. Not a scan report you cannot act on.
Website care plans
Hosting, security updates, tested backups and your monthly changes. For any small business site, whether I wrote it or not.
