PTENES
TRILHA 3

🖥️ Your Own Server

Get and secure your own cloud server: VPS, SSH, firewall, and access management. You’ll leave with your own machine running 24/7, accessed through a secure tunnel and protected against intruders.

4
Modules
24
Topics
~3h
Duration
Intermediate
Level
YOU bare server VPS Cloud PC SSH secure tunnel FIREWALL the gatekeeper TOKENS keys to the kingdom 🛡️ SECURE your server

Learning path map

Detailed Content

3.1 ~45 min

🖥️ VPS

A VPS is your PC in the cloud: a Linux machine that stays on 24 hours a day, accessible from anywhere in the world. Here you'll sign up, access it, and take care of your first one.

What it is:

VPS stands for Virtual Private Server. It is a piece of a powerful computer in a data center, dedicated to you and running day and night.

Why learn:

With a VPS, you can host websites, bots, databases, and APIs without depending on ready-made services. It's your computer in the cloud, under your full control.

Key concepts:

A VPS has a fixed public IP, runs Linux, and stays on all the time. Unlike your laptop, it doesn’t shut down when you close the lid.

What it is:

Providers are companies that rent VPSs by the month. DigitalOcean is simple and has lots of tutorials, Hetzner offers great value, and Contabo provides lots of resources at a low price.

Why learn:

Choosing the right provider helps you avoid overpaying or getting locked in. To get started, any of the three will work; the differences are price, data center location, and support.

Key concepts:

Compare monthly price, RAM, vCPU, and region. Choose a data center near your users so the site responds faster.

What it is:

The step-by-step process for creating an account, choosing the cheapest plan (the “droplet” or “server”), selecting Ubuntu, and clicking to create the machine.

Why learn:

It’s the moment the machine comes into existence. In just a few minutes, you get a public IP and an access password ready to use.

Key concepts:

Choose Ubuntu LTS, the lowest-priced plan, and a nearby region. Write down the IP and root password the provider shows at the end.

What it is:

Every provider offers a web console: a terminal that opens in your browser and connects you to the server without needing any software.

Why learn:

It’s the fastest way to access the server for the first time, even before setting up SSH. It works even when normal access breaks.

Key concepts:

Log in as root with the password the provider sent. The web console is your emergency plan B: keep this path handy.

What it is:

An overview of how the server’s Linux system works: the root user (the boss), regular users, the folder tree, and file permissions.

Why learn:

The server has no windows or buttons to click: everything is a command. Understanding users and permissions helps you avoid breaking the system or opening security gaps.

Key concepts:

Create a regular user and use sudo instead of running as root. whoami shows who you are; permissions control who can read and write.

What it is:

The server care commands: apt update e apt upgrade to update programs, and check disk space and memory.

Why learn:

An outdated server with open ports is an invitation to attackers. Updating regularly fixes security vulnerabilities and keeps everything running.

Key concepts:

Run apt update && apt upgrade every week. Use df -h to check disk space and free -h to check memory.

View Full
3.2 ~45 min

🔐 SSH

SSH is the secret tunnel between your computer and the server: everything that passes through it is encrypted. With keys, you can log in without typing a password and with much greater security.

What it is:

SSH (Secure Shell) is a protocol that creates an encrypted tunnel between your computer and the server. Everything you type travels securely.

Why learn:

It’s the standard way to control any Linux server in the world. Without SSH, you can’t safely operate remote machines.

Key concepts:

Think of an armored tunnel: no one along the way can read what passes through. The server listens for SSH on port 22 by default.

What it is:

The command ssh-keygen creates a pair of keys: one private (only you keep it) and one public (goes to the server). Together, they prove who you are.

Why learn:

Keys are more secure than passwords: they can't be guessed and don't travel over the network. They're the foundation of passwordless access.

Key concepts:

The private (id_ed25519) never leaves your PC; the public one (.pub) can be distributed. Protect the private one with a passphrase.

What it is:

The step of taking your public key to the server, usually with ssh-copy-id, which puts it in the file authorized_keys.

Why learn:

Without the public key on the server, it won’t recognize your private key. This step connects the two ends of the tunnel.

Key concepts:

ssh-copy-id usuario@ip does everything at once. The key is in ~/.ssh/authorized_keys inside the server.

What it is:

The command ssh usuario@ip opens the connection to the server. If the keys are correct, you get right in without entering a password.

Why learn:

It’s your gateway to everyday work on the server. From here on, every command you run happens there, in the cloud.

Key concepts:

The first time you connect, it asks about the "fingerprint": type yes. Use exit to leave and get back to your PC.

What it is:

The file ~/.ssh/config stores aliases for your servers, with IP, username, and key. That way, you type ssh meuserver instead of the entire command.

Why learn:

Remembering IPs and flags is tedious and error-prone. A well-made alias makes access instant and helps organize multiple machines.

Key concepts:

Each block starts with Host apelido and lists HostName, User e IdentityFile. One file, multiple servers.

What it is:

A server setting that prohibits password login and requires an SSH key. Edit sshd_config closes the door to anyone without the key.

Why learn:

Passwords can be cracked by brute force; keys can’t. Disabling password authentication eliminates the biggest source of server break-ins in one go.

Key concepts:

Define PasswordAuthentication no and restart SSH. Test the key first before closing the password, so you don’t lock yourself out.

View Full
3.3 ~45 min

🛡️ Firewall

The firewall is the server’s doorman: it decides which ports stay open and who can get in. With it, you expose only what’s necessary and block the rest of the world.

What it is:

A firewall is a filter that decides which traffic enters and leaves the server, port by port. It's a doorman who checks each connection before letting it through.

Why learn:

Without a firewall, every service is exposed to the internet. With one, you open only what you need and close the rest, greatly reducing the risk of a breach.

Key concepts:

Services listen on numbered “ports.” The firewall uses rules to allow and deny traffic by port and source.

What it is:

UFW (Uncomplicated Firewall) is the easy way to manage the firewall on Ubuntu. With a few commands, you can allow or deny entire ports.

Why learn:

The Linux firewall by itself is complex. UFW turns everything into simple, readable commands, ideal for those just getting started.

Key concepts:

ufw allow 22 opens, ufw deny close and ufw enable starts. ufw status shows the active rules.

What it is:

The three ports almost every web server needs: 22 for SSH, 80 for HTTP and 443 for HTTPS.

Why learn:

Knowing what each port is for helps you avoid two classic mistakes: leaving everything open or closing the SSH port and losing access.

Key concepts:

Open 22 (access), 80, and 443 (site), and close the rest. Never block 22 without another guaranteed way in.

What it is:

Fail2ban is a program that monitors logs and automatically bans any IP that enters the wrong password too many times in a row, blocking brute-force attacks.

Why learn:

Servers on the internet receive thousands of hacking attempts every day. Fail2ban responds automatically, so you don't have to keep an eye on it.

Key concepts:

It creates "jails" (chains) that monitor services like SSH. After X failed attempts, the IP gets banned for a set period.

What it is:

Let's Encrypt is an authority that issues free SSL certificates. With the tool certbot, your site starts using HTTPS with the padlock.

Why learn:

HTTPS encrypts your site's traffic and is required by browsers. Without a padlock, users see "site not secure" warnings.

Key concepts:

O certbot issues and renews the certificate automatically. HTTPS uses port 443 (remember to open it in the firewall).

What it is:

A checklist that brings together the protections in the learning path: regular user, SSH key, password login disabled, firewall enabled, Fail2ban, and HTTPS.

Why learn:

Security is the sum of several layers. A checklist ensures you haven’t forgotten any and that your server is locked down.

Key concepts:

Go through each item before putting anything important online. Repeat the checklist whenever you create a new server.

View Full
3.4 ~45 min

🎫 Tokens and Access

Tokens are the keys to the kingdom: they grant access to APIs and services. Here, you’ll learn how to store them, rotate them, and audit who gets in, without ever exposing a secret.

What it is:

An overview of the main types of credentials: API key (simple key), JWT (token signed with data), PAT (GitHub personal token), and OAuth (delegated access).

Why learn:

Each service uses a different type of token. Knowing how to tell them apart helps you avoid mixing up credentials or using the wrong one in the wrong place.

Key concepts:

An API key is the simplest; JWT carries information inside; OAuth is "Sign in with Google." They all prove who you are to the service.

What it is:

The practice of storing tokens in environment variables, usually in a file .env that stays outside the code and outside Git.

Why learn:

A token written directly in the code can easily leak to GitHub and the internet. The .env separates the secret from the program.

Key concepts:

Add .env when .gitignore always. Adjust the file permissions so only the owner can read it.

What it is:

Rotation is the habit of changing tokens from time to time; expiration is setting an expiration date so they stop working on their own.

Why learn:

A token that lasts forever is dangerous: if it leaks, the damage is permanent. Rotating it limits how long a leak can cause damage.

Key concepts:

Prefer tokens with short expiration periods. When you replace one, revoke the old one. If you suspect a leak, rotate it immediately.

What it is:

Secrets managers are digital vaults that securely store tokens and passwords, control access, and record who used each secret.

Why learn:

When the project grows, spreading files .env becomes a mess and a risk. A central vault organizes and protects all secrets.

Key concepts:

Examples: Vault, AWS Secrets Manager, Doppler. The core idea is: the secret is never in the code; it always comes from the vault when needed.

What it is:

Auditing means checking the server logs to find out who logged in, when, and what they did. On Linux, commands such as last and the authentication logs show this.

Why learn:

If something goes wrong, the logs tell the story. Monitoring access helps you spot an intrusion or misuse early.

Key concepts:

last lists the latest logins; /var/log/auth.log stores the attempts. Unusual attempts are a sign of an attack.

What it is:

A set of golden rules for handling tokens and access: least privilege possible, never commit secrets to version control, and separate environments (test and production).

Why learn:

Most leaks come from carelessness, not genius hackers. Following best practices eliminates the most common and dangerous mistakes.

Key concepts:

Give each token only the minimum access it needs. Never paste a secret into code or chat. Always keep test and production tokens separate.

View Full
← Back to the beginning Next Track →