Summary
- Secure Linux web hosting setup, hardening, and HTTPS configuration for self-hosted cloud servers.
- Guides users through nine phases: intake, prerequisites, secure access, firewall, web server, static site or reverse proxy, HTTPS, validation, and optional tuning Verifies distro-specific package names, service units, config paths, and ACME client guidance against official documentation before giving commands Enforces safety gates: key-based SSH must work before hardening, DNS must resolve before certificate issuance, HTTPS must load before forcing redirects Covers Nginx static-site hosting, reverse-proxy app setup, Let's Encrypt or ACME clients, SSH hardening, firewall rules, and post-launch network tuning like BBR