Security & TLS
A public web server is scanned by bots within minutes of going online, so security is not an optional appendix — it is part of setup. This collection covers TLS certificates with Let's Encrypt, firewall rules with ufw, SSH hardening, and the permissions hygiene that keeps a compromise contained. Security guides here are deliberately conservative: we recommend the well-trodden path (Certbot, ufw, key-based SSH) over clever exotic setups, we explain what each hardening step actually defends against, and we say plainly when a step is precautionary rather than critical.