Runfold

Fill in your context once. Read at the depth you need.

Series

Example

One real, short tutorial that uses every feature of this site. It is the page the guided tour lands on, and the reference when writing new ones.

  1. 01DraftSecure SSH on a fresh serverTen minutes after delivery, before anything else: a personal account, key-only login, a non-default port, a firewall, and a ban on brute force.beginner· ~10 min hands-on
Series

Kubernetes

From a few Linux machines to a small production-grade k3s cluster, then a real web application on it — indicat, thudal's SaaS prototype — with a database, TLS and continuous deployment.

  1. 01DraftBootstrap a k3s clusterFrom one to three Ubuntu machines to a working Kubernetes: k3s pinned to a version, kubectl and helm on your laptop, the bundled Traefik ingress, cert-manager with a ClusterIssuer, and a hello-world behind HTTPS to prove the whole chain.intermediate· ~40 min hands-on
  2. 02DraftDeploy indicatA real web application on the cluster: a namespace, its secrets, PostgreSQL (operator or StatefulSet), the Deployment with probes and limits, migrations, a Service, an Ingress with TLS at your domain, and an autoscaler.intermediate· ~50 min hands-on
  3. 03DraftDeploy on push with CIA ServiceAccount that can only touch your namespace, its kubeconfig as a CI secret, and a pipeline that builds the image on every push, tags it with the commit, and rolls it out.intermediate· ~35 min hands-on
Series

NetBox

NetBox is the source of truth for your network: devices, IPs, cables, circuits. This series takes it from a blank server to something you maintain and automate against.

  1. 01DraftInstall NetBox from scratchFrom a fresh Linux server to a NetBox instance behind HTTPS, ready for users. PostgreSQL, Redis, NetBox itself, gunicorn, then the web server you choose.intermediate· ~45 min hands-on
  2. 02DraftConfigure NetBox for your teamThe settings you want before opening NetBox to colleagues: time zone and banners, outgoing mail, groups and permissions, the first plugins, and the custom fields your data needs.intermediate· ~40 min hands-on
  3. 03DraftMaintain and upgrade NetBoxNightly backups you have actually restored once, an upgrade path you can roll back, the housekeeping job, log rotation, and a probe that tells you NetBox is alive.intermediate· ~35 min hands-on
  4. 04DraftAutomate NetBox with the APIA scoped automation user, pynetbox or curl to read and write, a CSV import that survives errors, webhooks on device changes, and a custom script run from the API.intermediate· ~45 min hands-on
Series

NetDevOps lab

A network lab you can rebuild in minutes: a containerlab topology, NetBox as the source of truth, configuration generated and pushed from it, and a CI pipeline that proves every change before it reaches the lab.

  1. 01DraftA network lab with containerlabDocker and containerlab on one Linux machine, a network OS image, a spine and two leaves wired together, a first interface configuration, and the whole thing in a git repository.beginner· ~30 min hands-on
  2. 02DraftModel the lab in NetBoxWhat belongs in a source of truth and what does not, then a pynetbox script that creates the site, the devices, their interfaces, addresses and cables, and a config context with the BGP numbers. Safe to run twice.intermediate· ~40 min hands-on
  3. 03DraftGenerate and push configs from NetBoxAn inventory read from NetBox, one Jinja2 template per network OS, a renderer that writes one file per device, a push with a dry run first, and BGP established between the spine and its leaves without typing a single address.intermediate· ~45 min hands-on
  4. 04DraftValidate every change in CIA lint stage on a hosted runner, a lab stage on a self-hosted runner that deploys the topology, renders, pushes, runs a pytest with scrapli and always tears down, artifacts, and a protected main branch that only merges what the pipeline proved.advanced· ~40 min hands-on
Series

A static site on an OVH VPS

From a Next.js project on your laptop to a site served over HTTPS from your own Debian VPS at OVH, with a domain managed at Infomaniak, atomic deploys, backups and monitoring. Eight pages, in the order you do them.

  1. 01DraftPrepare your laptopBefore ordering anything: the site builds cleanly from scratch, you know what you are about to ship, the project folder (the only original of the site) is backed up, and ssh on your Mac keeps passphrases in the Keychain. The server's SSH key is made on the next page.beginner· ~20 min hands-on
  2. 02DraftOrder the VPS at OVHA Debian 13 VPS ordered in the OVH control panel, delivered, and reachable as the user debian with an SSH key made for it (~/.ssh/id_ed25519_vps), its public half in the values panel. Its IPv4 and IPv6 are noted, and the OVH account that controls it is protected by two-factor authentication.beginner· ~15 min hands-on
  3. 03DraftSecure the server in the first hourFrom OVH's default `debian` login to your own admin account with a key and a sudo password, SSH on its own port with passwords and root refused, a firewall, bans on brute force, and security updates that install themselves. Every lock is tested before the old door closes.intermediate· ~30 min hands-on
  4. 04DraftPoint the domain at the server (Infomaniak DNS)Your domain and its www answer with the VPS in IPv4 and IPv6, only Let's Encrypt (and optionally ZeroSSL) may issue certificates for it, and nobody can send mail in its name — or your Infomaniak mailbox keeps working, with DMARC on top. Clicks in the Manager, checks with dig.beginner· ~20 min hands-on
  5. 05DraftServe the site with Caddy and HTTPSCaddy installed from its official repository, serving a placeholder page from the web root over HTTPS with a Let's Encrypt certificate it renews by itself. www and plain HTTP redirect to the bare domain (nothing in front), HTTP/3 is on, security headers and caching are set, access logs are rotated.intermediate· ~20 min hands-on
  6. 06DraftDeploy atomic releases with rsyncOne command on your laptop builds the site, uploads only what changed into a new release directory, switches the live site to it in a single atomic step, keeps the last few releases and checks the result. Rollback is one command too.intermediate· ~30 min hands-on
  7. 07DraftBackups, monitoring and the monthly routineKnow what is worth saving on the server and what is not. An encrypted off-site copy made every night by restic, with a restore you have actually tested; an email when the site goes down or the backup did not run; logs that cannot fill the disk; and a ten-minute check once a month.intermediate· ~40 min hands-on
  8. 08DraftLaunch checklistBefore you announce the site: robots.txt and sitemap.xml generated by Next.js, the heaviest files trimmed, and everything the previous pages set up verified from the outside — redirects, 404, certificate, headers, IPv6, HTTP/3, performance — with one script that prints PASS or FAIL.beginner· ~30 min hands-on
Series

A private VPS behind WireGuard

From a hardened Debian VPS (pages 1 to 3 of "A static site on an OVH VPS") to a server that answers no one on the internet but your own devices, through a WireGuard tunnel you run yourself: no third party in the path, a single UDP port open, every service reachable only from inside.

  1. 01DraftOpen a WireGuard tunnel to the serverWireGuard running on the server on one UDP port, your Mac (and your phone if you want) connected to it with keys generated on each device, and ssh reaching the server through the tunnel under a new shortcut. The public SSH port stays open: page 2 closes it.intermediate· ~25 min hands-on
  2. 02DraftClose the public doorSSH taken off the internet and kept on the tunnel only, checked from outside, proven to survive a reboot, with the way back in written down before you need it. The server's only open port is now WireGuard's, which answers nothing to anyone without a key.intermediate· ~15 min hands-on