Learning path map
Detailed Content
🖥️ VPS
A VPS is your PC in the cloud: a Linux machine that stays on 24 hours a day, accessible from anywhere in the world. Here you'll sign up, access it, and take care of your first one.
VPS stands for Virtual Private Server. It is a piece of a powerful computer in a data center, dedicated to you and running day and night.
With a VPS, you can host websites, bots, databases, and APIs without depending on ready-made services. It's your computer in the cloud, under your full control.
A VPS has a fixed public IP, runs Linux, and stays on all the time. Unlike your laptop, it doesn’t shut down when you close the lid.
Providers are companies that rent VPSs by the month. DigitalOcean is simple and has lots of tutorials, Hetzner offers great value, and Contabo provides lots of resources at a low price.
Choosing the right provider helps you avoid overpaying or getting locked in. To get started, any of the three will work; the differences are price, data center location, and support.
Compare monthly price, RAM, vCPU, and region. Choose a data center near your users so the site responds faster.
The step-by-step process for creating an account, choosing the cheapest plan (the “droplet” or “server”), selecting Ubuntu, and clicking to create the machine.
It’s the moment the machine comes into existence. In just a few minutes, you get a public IP and an access password ready to use.
Choose Ubuntu LTS, the lowest-priced plan, and a nearby region. Write down the IP and root password the provider shows at the end.
Every provider offers a web console: a terminal that opens in your browser and connects you to the server without needing any software.
It’s the fastest way to access the server for the first time, even before setting up SSH. It works even when normal access breaks.
Log in as root with the password the provider sent. The web console is your emergency plan B: keep this path handy.
An overview of how the server’s Linux system works: the root user (the boss), regular users, the folder tree, and file permissions.
The server has no windows or buttons to click: everything is a command. Understanding users and permissions helps you avoid breaking the system or opening security gaps.
Create a regular user and use sudo instead of running as root. whoami shows who you are; permissions control who can read and write.
The server care commands: apt update e apt upgrade to update programs, and check disk space and memory.
An outdated server with open ports is an invitation to attackers. Updating regularly fixes security vulnerabilities and keeps everything running.
Run apt update && apt upgrade every week. Use df -h to check disk space and free -h to check memory.
🔐 SSH
SSH is the secret tunnel between your computer and the server: everything that passes through it is encrypted. With keys, you can log in without typing a password and with much greater security.
SSH (Secure Shell) is a protocol that creates an encrypted tunnel between your computer and the server. Everything you type travels securely.
It’s the standard way to control any Linux server in the world. Without SSH, you can’t safely operate remote machines.
Think of an armored tunnel: no one along the way can read what passes through. The server listens for SSH on port 22 by default.
The command ssh-keygen creates a pair of keys: one private (only you keep it) and one public (goes to the server). Together, they prove who you are.
Keys are more secure than passwords: they can't be guessed and don't travel over the network. They're the foundation of passwordless access.
The private (id_ed25519) never leaves your PC; the public one (.pub) can be distributed. Protect the private one with a passphrase.
The step of taking your public key to the server, usually with ssh-copy-id, which puts it in the file authorized_keys.
Without the public key on the server, it won’t recognize your private key. This step connects the two ends of the tunnel.
ssh-copy-id usuario@ip does everything at once. The key is in ~/.ssh/authorized_keys inside the server.
The command ssh usuario@ip opens the connection to the server. If the keys are correct, you get right in without entering a password.
It’s your gateway to everyday work on the server. From here on, every command you run happens there, in the cloud.
The first time you connect, it asks about the "fingerprint": type yes. Use exit to leave and get back to your PC.
The file ~/.ssh/config stores aliases for your servers, with IP, username, and key. That way, you type ssh meuserver instead of the entire command.
Remembering IPs and flags is tedious and error-prone. A well-made alias makes access instant and helps organize multiple machines.
Each block starts with Host apelido and lists HostName, User e IdentityFile. One file, multiple servers.
A server setting that prohibits password login and requires an SSH key. Edit sshd_config closes the door to anyone without the key.
Passwords can be cracked by brute force; keys can’t. Disabling password authentication eliminates the biggest source of server break-ins in one go.
Define PasswordAuthentication no and restart SSH. Test the key first before closing the password, so you don’t lock yourself out.
🛡️ Firewall
The firewall is the server’s doorman: it decides which ports stay open and who can get in. With it, you expose only what’s necessary and block the rest of the world.
A firewall is a filter that decides which traffic enters and leaves the server, port by port. It's a doorman who checks each connection before letting it through.
Without a firewall, every service is exposed to the internet. With one, you open only what you need and close the rest, greatly reducing the risk of a breach.
Services listen on numbered “ports.” The firewall uses rules to allow and deny traffic by port and source.
UFW (Uncomplicated Firewall) is the easy way to manage the firewall on Ubuntu. With a few commands, you can allow or deny entire ports.
The Linux firewall by itself is complex. UFW turns everything into simple, readable commands, ideal for those just getting started.
ufw allow 22 opens, ufw deny close and ufw enable starts. ufw status shows the active rules.
The three ports almost every web server needs: 22 for SSH, 80 for HTTP and 443 for HTTPS.
Knowing what each port is for helps you avoid two classic mistakes: leaving everything open or closing the SSH port and losing access.
Open 22 (access), 80, and 443 (site), and close the rest. Never block 22 without another guaranteed way in.
Fail2ban is a program that monitors logs and automatically bans any IP that enters the wrong password too many times in a row, blocking brute-force attacks.
Servers on the internet receive thousands of hacking attempts every day. Fail2ban responds automatically, so you don't have to keep an eye on it.
It creates "jails" (chains) that monitor services like SSH. After X failed attempts, the IP gets banned for a set period.
Let's Encrypt is an authority that issues free SSL certificates. With the tool certbot, your site starts using HTTPS with the padlock.
HTTPS encrypts your site's traffic and is required by browsers. Without a padlock, users see "site not secure" warnings.
O certbot issues and renews the certificate automatically. HTTPS uses port 443 (remember to open it in the firewall).
A checklist that brings together the protections in the learning path: regular user, SSH key, password login disabled, firewall enabled, Fail2ban, and HTTPS.
Security is the sum of several layers. A checklist ensures you haven’t forgotten any and that your server is locked down.
Go through each item before putting anything important online. Repeat the checklist whenever you create a new server.
🎫 Tokens and Access
Tokens are the keys to the kingdom: they grant access to APIs and services. Here, you’ll learn how to store them, rotate them, and audit who gets in, without ever exposing a secret.
An overview of the main types of credentials: API key (simple key), JWT (token signed with data), PAT (GitHub personal token), and OAuth (delegated access).
Each service uses a different type of token. Knowing how to tell them apart helps you avoid mixing up credentials or using the wrong one in the wrong place.
An API key is the simplest; JWT carries information inside; OAuth is "Sign in with Google." They all prove who you are to the service.
The practice of storing tokens in environment variables, usually in a file .env that stays outside the code and outside Git.
A token written directly in the code can easily leak to GitHub and the internet. The .env separates the secret from the program.
Add .env when .gitignore always. Adjust the file permissions so only the owner can read it.
Rotation is the habit of changing tokens from time to time; expiration is setting an expiration date so they stop working on their own.
A token that lasts forever is dangerous: if it leaks, the damage is permanent. Rotating it limits how long a leak can cause damage.
Prefer tokens with short expiration periods. When you replace one, revoke the old one. If you suspect a leak, rotate it immediately.
Secrets managers are digital vaults that securely store tokens and passwords, control access, and record who used each secret.
When the project grows, spreading files .env becomes a mess and a risk. A central vault organizes and protects all secrets.
Examples: Vault, AWS Secrets Manager, Doppler. The core idea is: the secret is never in the code; it always comes from the vault when needed.
Auditing means checking the server logs to find out who logged in, when, and what they did. On Linux, commands such as last and the authentication logs show this.
If something goes wrong, the logs tell the story. Monitoring access helps you spot an intrusion or misuse early.
last lists the latest logins; /var/log/auth.log stores the attempts. Unusual attempts are a sign of an attack.
A set of golden rules for handling tokens and access: least privilege possible, never commit secrets to version control, and separate environments (test and production).
Most leaks come from carelessness, not genius hackers. Following best practices eliminates the most common and dangerous mistakes.
Give each token only the minimum access it needs. Never paste a secret into code or chat. Always keep test and production tokens separate.