Welcome to the ByteGeist Cloud Lab.
ByteGeist is a self-hosted cloud environment built to develop practical skills in Linux administration, Docker, networking, reverse proxies, identity management, observability, security, backup management, disaster recovery, automation, CI/CD, hybrid cloud integration, and modern infrastructure operations.
| Item | Value |
|---|---|
| Provider | Hetzner |
| Operating System | Ubuntu 24.04 |
| CPU | 2 vCPU |
| Memory | 4 GB |
| Storage | 80 GB SSD |
| Public IP | 95.216.204.54 |
| Container Platform | Docker |
| Container Management | Portainer |
| Reverse Proxy | Nginx Proxy Manager |
| Running Containers | 26 |
| Cloud Provider | AWS |
| Offsite Backup | AWS S3 |
| AWS Audit Logging | CloudTrail |
| Resource | Usage |
|---|---|
| CPU | ~15% |
| Memory | ~60-70% |
| Disk | ~35% |
| Free Disk | ~48 GiB |
Status:
✅ Operational
Purpose:
Offsite backup storage, AWS security baseline, audit logging, and future hybrid cloud expansion.
Implemented Components:
us-east-2Current AWS Account:
227755136653
Backup Bucket:
bytegeist-backups-227755136653
Backup Prefix:
s3://bytegeist-backups-227755136653/hetzner/bytegeist-cloud/
ByteSpace Backup Bucket:
bytespace-backups-227755136653
CloudTrail Log Bucket:
bytegeist-cloudtrail-logs-227755136653
Cost Controls:
Security Controls:
Migration Validation:
Status:
✅ Operational
Purpose:
Docker container management.
URL:
Authentication:
Protected by Authentik
Status:
✅ Operational
Purpose:
Reverse proxy and SSL management.
URL:
Status:
✅ Operational
Purpose:
Centralized Identity Provider
URL:
Features:
Containers:
Protected Applications:
Status:
✅ Operational
URL:
Authentication:
Protected by Authentik
Dashboards:
Status:
✅ Operational
Purpose:
Metrics Collection
Status:
✅ Operational
Purpose:
Linux Host Metrics
Status:
✅ Operational
Purpose:
Docker Container Metrics
Status:
✅ Operational
Purpose:
Availability Monitoring
URL:
Status:
✅ Operational
Purpose:
Server Monitoring
URL:
Status:
✅ Operational
Purpose:
Centralized Log Aggregation
Status:
✅ Operational
Purpose:
Log Collection & Shipping
Status:
✅ Operational
Purpose:
Live Docker Log Viewer
URL:
Status:
✅ Operational
Purpose:
Git Repository Hosting
URL:
Status:
✅ Operational
Purpose:
Documentation Platform
URL:
Status:
✅ Operational
Purpose:
Continuous Integration & Continuous Deployment
URL:
Authentication:
Gitea OAuth
Features:
Components:
Status:
✅ Operational
Deployment Date:
2026-06-20
Verified:
✅ Pipeline Execution Successful
Purpose:
Service Dashboard
URL:
Status:
✅ Operational
Purpose:
Password Management
URL:
Authentication:
Protected by Authentik
Status:
✅ Operational
Purpose:
Web-Based File Management
URL:
Status:
✅ Operational
Purpose:
Network & Development Utilities
URL:
Authentication:
Protected by Authentik
Status:
✅ Operational
Purpose:
PDF Processing Platform
URL:
Authentication:
Protected by Authentik
Status:
✅ Operational
| Domain | Service |
|---|---|
| auth.casko.dev | Authentik |
| lab.casko.dev | Portainer |
| proxy.casko.dev | Nginx Proxy Manager |
| grafana.casko.dev | Grafana |
| status.casko.dev | Uptime Kuma |
| monitor.casko.dev | Beszel |
| logs.casko.dev | Dozzle |
| git.casko.dev | Gitea |
| wiki.casko.dev | Wiki.js |
| ci.casko.dev | Woodpecker CI |
| home.casko.dev | Dashy |
| vault.casko.dev | Vaultwarden |
| files.casko.dev | File Browser |
| tools.casko.dev | IT-Tools |
| pdf.casko.dev | Stirling PDF |
✅ UFW Firewall Enabled
✅ Default Deny Incoming
✅ Only Ports 22, 80, 443 Exposed
✅ HTTPS Everywhere
✅ Authentik Single Sign-On
✅ Authentik Two-Factor Authentication
✅ ED25519 SSH Keys
✅ Password Authentication Disabled
✅ Root Password Login Disabled
Current SSH Configuration:
PermitRootLogin prohibit-password
PubkeyAuthentication yes
PasswordAuthentication no
Status:
✅ Operational
Capabilities:
Status:
✅ Operational
Installed Components:
Detection Capabilities:
Verified:
✅ Detection Active
✅ Bouncer Connected
✅ Automated Enforcement Enabled
✅ Grafana
✅ Prometheus
✅ Loki
✅ Alloy
✅ Centralized Logging
✅ Infrastructure Monitoring
Schedule:
Daily at 2:00 AM
Backup Script:
/opt/scripts/backup-bytegeist.sh
Backup Storage:
/srv/filebrowser/backups
Retention:
7 Days
Status:
✅ Operational
Project:
ByteGeist CloudBridge Phase 1
Purpose:
Automated offsite backups from the Hetzner VPS to AWS S3.
Backup Script:
/root/bytegeist-backups/scripts/backup-bytegeist-to-s3.sh
Status Script:
/root/bytegeist-backups/scripts/backup-status.sh
Schedule:
Daily at 06:15 UTC with randomized delay
Backup Storage:
s3://bytegeist-backups-227755136653/hetzner/bytegeist-cloud/
Validation:
Status:
✅ Operational
Latest Verified Local Backup:
/root/backups/bytegeist-full-2026-06-19.tar.gz
Latest Verified Offsite Backup:
bytegeist-full-2026-08-02_01-37-07.tar.gz
Status:
✅ Recoverable
Documentation:
Available
Includes:
Status:
✅ Operational
227755136653✅ Monitoring
✅ Centralized Logging
✅ Identity Management
✅ Single Sign-On
✅ Two-Factor Authentication
✅ Backup Automation
✅ Offsite AWS S3 Backups
✅ Backup Validation
✅ Disaster Recovery Documentation
✅ SSH Hardening
✅ Fail2Ban
✅ CrowdSec
✅ CI/CD
✅ AWS CloudBridge Phase 1 and Account Consolidation
✅ Service Documentation
🚧 Grafana Alerting
🚧 Security Dashboard
🚧 Portfolio Development
🚧 Database-Aware Backup Upgrade
ByteGeist provides hands-on experience with:
✅ 22+ Services Operational
✅ Operational
✅ Operational
✅ Operational
✅ Operational
✅ Operational
✅ Operational
✅ Operational
✅ Operational
✅ Current
| Capability | Status |
|---|---|
| Linux Administration | ✅ |
| Docker | ✅ |
| Reverse Proxy | ✅ |
| SSL/TLS | ✅ |
| Identity Management | ✅ |
| Single Sign-On | ✅ |
| Two-Factor Authentication | ✅ |
| Monitoring | ✅ |
| Logging | ✅ |
| Security Hardening | ✅ |
| Threat Detection | ✅ |
| Backup Automation | ✅ |
| Disaster Recovery | ✅ |
| Git Hosting | ✅ |
| CI/CD | ✅ |
| Offsite Backups | ✅ |
| AWS S3 | ✅ |
| AWS IAM | ✅ |
| AWS CloudTrail | ✅ |
| AWS Cost Controls | ✅ |
| Cross-Account Migration | ✅ |
| Hybrid Cloud Integration | ✅ |
| Documentation | ✅ |
Last Updated: August 2, 2026
Version: 1.9