05Infrastructure
Where all of this runs.
A small network of machines I configure, monitor and fix: production in the cloud, builds at home and the store counter, all connected over VPN.
Certificates that renew themselves, services that restart on their own and a migration checked system by system.
- Linux
- Docker
- systemd
- nginx
- WireGuard
- Let's Encrypt
The problem
Everything I build needs a place to live, with HTTPS, secure access and no downtime. And without an infrastructure team to take care of it.
What I built
- Linux servers with Docker and systemd running the systems I maintain and this portfolio.
- nginx in front of everything, with Let's Encrypt certificates that renew themselves and security headers.
- SSH key-only access, a firewall closed by default and ports opened only for whoever needs them.
- WireGuard VPNs connecting only the points that need to talk, such as a store counter and the build machine.
- A full hosting provider migration, with every system checked before the old server was shut down.
How it works
Entry
nginx receives the traffic, handles HTTPS and routes each domain to its service.
Services
APIs and queues run under systemd, which restarts them on its own; databases and tools run in containers.
Private networks
Databases only listen inside the server. Anything that needs to leave goes through the VPN.
Operations
Claude agents, reachable over Telegram, help me inspect and fix the server.
Decisions that mattered
Migrate by checking, not trusting
Why: During the provider switch, every service, table and screen was checked on the new server before the old one was turned off. Nothing was lost.
A VPN that isn't an internet exit
Why: The server only forwards traffic between points of the same VPN. The home network stays out of the route, always.
Services that come back on their own
Why: Everything of mine runs as a service with automatic restart. If it goes down at 3am, it gets back up without me.
What went wrong
Every real system breaks somehow. These were the stumbles that taught the most, and what changed because of them.
A VPN that broke the home network
What happened
An old tunnel listed the local network's range among the traffic that goes through the VPN. Everything headed for the house itself went into the tunnel and died there, and nobody noticed for weeks because day-to-day work was with outside servers.
What changed
The local network never goes into a VPN. And the new VPN is not an internet exit: it only carries traffic between its own peers.
The service that didn't come back
What happened
To restart an API, I ended the process by name. It exited cleanly, and the service manager, set to restart only on failure, didn't bring it back. The API was down with no alarm.
What changed
Restarts only through the service manager, and processes are only ended by their ID. After restarting, I check that it's the service that is up, not a stray process.
The tunnel that came up and died every minute
What happened
After a macOS update, the home machine's tunnel went into a loop: the guard brought it up, the system killed it along with the process that created it, and the log reported success every time.
What changed
One configuration key fixed it. The lesson was bigger: a success log doesn't prove something is up. I test by bringing it up by hand and comparing.
Where it stands
Live. This site runs on it.