All services

Cloud & Server Management

End-to-end Linux infrastructure — provisioning, hardening, SSL, DNS, monitoring, backups and migrations handled for you.

Cloud & Server Management — an illustration of the tools and systems involved

What we deliver

18 services in this discipline. Each one says what it includes and how we approach it — no jargon, no vague promises.

    01

    VPS Setup & Management

    Provisioning, configuration and ongoing management of your virtual servers.

    Server provisioned, secured, configured for your stack and — importantly — documented, so it isn't a black box only one person understands. Ongoing management covers updates, monitoring, capacity review and incident response. You keep full root access and ownership of the server throughout.

    02

    Linux Server Administration

    Day-to-day upkeep of users, packages, services, logs and system resources.

    Users and permissions, package management, service supervision, log rotation and disk hygiene handled as routine work. This is the unglamorous maintenance that prevents the majority of outages we get called about. Changes are recorded so the server's history is knowable.

    03

    Ubuntu Server Setup

    Clean, secured Ubuntu builds prepared and tested for production workloads.

    A clean LTS build with only what you need installed, unattended security updates enabled, and base hardening completed before anything goes live. The build is reproducible, so your next server is identical rather than subtly different. Locale, timezone, swap and limits are set deliberately rather than left at defaults.

    04

    Docker Deployment

    Containerised applications that behave identically on every machine they run on.

    Applications containerised with sensible base images, health checks and resource limits, so behaviour is consistent across machines. We use Compose or full orchestration depending on how many services you genuinely run, not on what sounds impressive. Image builds are pinned and reproducible.

    05

    Nginx Configuration

    Virtual hosts, caching, compression and rate limiting configured the right way.

    Server blocks, TLS, HTTP/2, compression, caching headers, upload limits and rate limiting configured deliberately rather than copied from a blog post. Configuration is version-controlled and tested before reload, so a typo can't take the site down. Logs are formatted to be useful for debugging and analytics.

    06

    Apache Configuration

    Legacy and mixed stacks configured, tuned and kept stable.

    Virtual hosts, modules, rewrite rules and PHP handlers configured for stability, including mixed and legacy stacks. Useful when an existing application expects Apache specifically and rewriting it isn't worth the cost. We can also run Apache behind Nginx where that gives the best of both.

    07

    Reverse Proxy Setup

    Route multiple applications behind one domain with clean SSL termination.

    Multiple applications served behind one domain or IP, with clean SSL termination, correct forwarded headers and WebSocket support where needed. Adding a new service later becomes a small, safe configuration change. Internal services stay bound to localhost rather than being exposed directly.

    08

    SSL Installation

    Let's Encrypt or commercial certificates installed with renewal automated.

    Certificates issued and installed with renewal automated and monitored, so nothing expires unnoticed over a weekend. Correct chain, strong ciphers and redirects are tested end to end from outside the server. Wildcard and multi-domain certificates are handled where they simplify things.

    09

    Domain Configuration

    Domains pointed, redirected and mapped to the right services without downtime.

    Domains and subdomains pointed at the right services, with redirects, canonical hosts and www handling settled properly rather than left ambiguous. Changes are staged with lowered TTLs to avoid downtime during propagation. Registrar and DNS provider settings are documented for your records.

    10

    DNS Management

    A, CNAME, MX, TXT and SRV records set up correctly the first time.

    Records set correctly the first time, with sensible TTLs, and mail-related records verified against real delivery rather than assumed. We document the full zone so future changes are safe for whoever makes them. Propagation is checked from multiple resolvers before we call it done.

    11

    Cloudflare Setup

    CDN, WAF, caching rules and DDoS protection sitting in front of your site.

    Proxy, CDN caching rules, WAF, bot handling and DDoS protection configured to your traffic patterns rather than left on defaults. The origin server is locked down so it can only be reached through Cloudflare, closing the usual bypass. Page rules and cache behaviour are tuned so dynamic content isn't wrongly cached.

    12

    Server Security Hardening

    SSH keys, fail2ban, disabled root login and the smallest possible attack surface.

    Key-only SSH, no root login, fail2ban, minimal open ports, unattended security upgrades and removal of anything unnecessary. Each change is documented so you know exactly what was altered and why. We provide a short report you can show to a client or auditor.

    13

    Firewall Configuration

    UFW or iptables rules that allow exactly what is needed and nothing else.

    Rules built from an explicit allow-list of what your services genuinely need, with everything else denied by default. This includes traffic between your own servers, which is frequently left wide open. Rules are tested against real traffic before enforcement to avoid locking yourself out.

    14

    Performance Optimization

    Profiling and tuning so your server handles the load without paying for a bigger one.

    We profile before changing anything — CPU, memory, I/O, database queries and application hot paths — then fix the actual constraint. Frequently that costs far less than upgrading the server, and the upgrade wouldn't have helped anyway. Results are measured before and after so the improvement is provable.

    15

    Server Monitoring

    Uptime, CPU, memory, disk and service checks that alert you before users notice.

    Uptime, resources, service health, certificate expiry and log patterns watched continuously, with alerts routed where you'll actually see them. Thresholds are tuned so an alert always means something, otherwise people learn to ignore them. Historical graphs make capacity planning a decision rather than a guess.

    16

    Backup Solutions

    Automated off-site backups with a restore procedure that has actually been tested.

    Automated off-site backups on a defined retention schedule, encrypted at rest and in transit, with restores tested periodically. A backup you have never restored from is a hope rather than a plan. You receive a written restore procedure with realistic timings.

    17

    Server Migration

    Move to new hosting with minimal downtime and nothing left behind.

    Full inventory of what's actually running, staged synchronisation, DNS cutover with lowered TTLs, and a tested rollback plan ready before we start. Downtime is planned and usually measured in minutes rather than hours. The old server is kept intact until you confirm everything works.

    18

    High Availability Setup

    Load balancing and failover so one server going down doesn't take you offline.

    Load balancing across multiple nodes with health checks and automatic failover, plus database replication where the data layer supports it. Sized to your real traffic rather than a theoretical peak, because unnecessary complexity causes its own outages. Failover is tested deliberately, not discovered during an incident.

Let's talk

Need cloud & server management?

Tell us what you are trying to do. If we are not the right people for it, we will say so.