5 guides

Patching, backup & uptime

The boring work that prevents 80 % of incidents. These guides cover patching without surprises, backups that actually exist, certificates that do not expire silently and a status page your customers can read themselves.

Patching, backup & uptime
beginner · 7 min read
2026-09-16

Building a public status page without Statuspage.io: self-hosted, in 30 minutes, on a different server than your product

A status page on the same server as the service it describes is down when you need it. This is the setup that works: Uptime Kuma on a separate, cheap VPS, checks from outside on HTTP, TLS and TCP, a public page on status.yourdomain.com with its own certificate, incident updates you post from your phone, and the DNS and cache details that decide whether the page stays reachable when the rest is on fire.

status-pageuptime-kumauptimeincidentdockercaddy
Patching, backup & uptime
intermediate · 6 min read
2026-09-15

Updating the kernel on a production server: sequence, rollback plan and when livepatch is worth it

A kernel update is the only routine update that requires a reboot and that can leave your server hanging. This is the checklist we use ourselves: pre-checks (/boot, DKMS, Secure Boot), snapshot, installation, a GRUB fallback that automatically picks the old kernel after one failed boot, and the verification after the reboot. In a fifteen-minute window.

kernelrebootgrubdkmslivepatchubuntudebian
Patching, backup & uptime
beginner · 5 min read
2026-09-15

TLS certificates that expire silently: inventory the whole fleet and alert 14 days ahead

Let's Encrypt renews itself — until the day the hook fails, DNS validation breaks or someone removed the cron. This script finds every certificate on every port of every host (internal ones too, mail too, the reverse proxy nobody remembers), computes the remaining days and pushes an alert at 14 and 7 days. No Nagios, no external service.

tlscertificatesletsencryptopensslexpiryntfy
Patching, backup & uptime
beginner · 4 min read
2026-09-15

Configuring unattended-upgrades properly — and why you must monitor reboot-required

The default install of unattended-upgrades patches security updates but leaves services running on old libraries and the new kernel sitting on disk. This is the configuration that fixes that for Ubuntu 24.04 and Debian 12: origins, blacklist, needrestart, reboot policy, mail — plus the cron script that reports which hosts have been waiting days for a reboot.

unattended-upgradesaptneedrestartrebootubuntudebian
Patching, backup & uptime
beginner · 5 min read
2026-09-15

Verifying backups that say "succeeded": freshness, integrity and a restore test that logs itself

A backup job that returns exit 0 proves the job ran — not that there's anything usable in the archive. Three checks you automate: is the newest backup fresh enough (mtime check), is the archive readable (restic/borg check) and can you actually get something back out (monthly restore test with a log line). Plus the pitfall of rsync preserving mtimes.

backupresticborgrestoreiso27001ntfy

← All guides