Welcome to the ByteGeist Cloud Lab.
ByteGeist is a self-hosted infrastructure environment built to develop practical hands-on experience in:
- Linux administration
- Docker and container management
- Networking
- Reverse proxies
- SSL/TLS
- Identity and access management
- Monitoring and observability
- Centralized logging
- Security hardening
- Threat detection
- Backup and recovery
- Disaster recovery
- Automation
- CI/CD
- AWS cloud services
- Hybrid cloud integration
- Technical documentation
- Incident investigation and troubleshooting
The environment is designed as a continuously evolving systems administration and cloud engineering lab rather than a collection of isolated tutorials.
ByteGeist is used to build practical experience with:
- Linux Administration
- Docker & Container Management
- Reverse Proxies
- SSL/TLS Management
- Networking
- Identity & Access Management
- Monitoring & Alerting
- Centralized Logging
- Backup & Recovery
- Security Hardening
- Threat Detection
- Incident Investigation
- Documentation
- Automation
- CI/CD
- Portfolio Development
- System Administration
- Hybrid Cloud Integration
- AWS Fundamentals
| Item |
Configuration |
| Hosting Provider |
Hetzner |
| Operating System |
Ubuntu 24.04 |
| CPU |
2 vCPU |
| Memory |
4 GB |
| Storage |
80 GB SSD |
| Container Platform |
Docker |
| Container Management |
Portainer |
| Reverse Proxy |
Nginx Proxy Manager |
| Running Containers |
20+ |
| Cloud Provider |
AWS |
| Offsite Backup |
Amazon S3 |
| AWS Audit Logging |
CloudTrail |
Typical operating range:
| Resource |
Usage |
| CPU |
~15% |
| Memory |
~60-70% |
| Disk |
~35% |
Status: Operational
ByteGeist CloudBridge extends the Hetzner-hosted environment into AWS for:
- Offsite backups
- Cloud security controls
- Audit logging
- Cost monitoring
- Disaster recovery
- Hybrid cloud experimentation
- AWS IAM with MFA
- Least-privilege IAM identities
- Encrypted Amazon S3 backup storage
- S3 versioning
- S3 lifecycle policies
- Amazon S3 Public Access Block
- CloudTrail multi-region audit logging
- CloudTrail log-file validation
- AWS CLI integration
- Automated backup uploads
- AWS Budgets cost monitoring
- Cross-account data migration experience
- AES-256 server-side encryption
- Full S3 Public Access Block
- Bucket-owner-enforced object ownership
- Least-privilege IAM policies
- Separate backup identities
- MFA-protected AWS administration
- No root AWS credentials stored on the VPS
- Obsolete access keys removed after migration
- Temporary migration identities removed after use
During an AWS account consolidation and backup migration:
- Approximately 2.7 GiB of backup data was migrated
- Object counts were verified
- Storage totals were compared
- SHA-256 checksum validation was performed
- Live backup jobs were tested
- AWS CLI profiles were updated
- IAM permissions were rebuilt
- CloudTrail was recreated
- Old credentials and retired cloud resources were removed
Status: Operational
Purpose: Docker container management
URL:
https://lab.casko.dev
Authentication:
Authentik protected
Status: Operational
Purpose: Reverse proxy and SSL certificate management
URL:
https://proxy.casko.dev
Status: Operational
Purpose: Centralized identity provider and access control platform
URL:
https://auth.casko.dev
- Single Sign-On
- OAuth2
- OpenID Connect
- Forward Authentication
- Group Management
- Two-Factor Authentication
Authentik is deployed using containerized services including:
- Authentik server
- Authentik worker
- PostgreSQL
- Redis
Examples include:
- Grafana
- Portainer
- Vaultwarden
- IT-Tools
- Stirling PDF
Status: Operational
URL:
https://grafana.casko.dev
Authentication:
Authentik protected
Tracks:
- Service availability
- Server uptime
- CPU utilization
- Memory utilization
- Running containers
- Disk utilization
- Free disk space
- System load
- Container CPU usage
- Container memory usage
Node Exporter metrics include:
- CPU
- Memory
- Filesystems
- Network activity
- System load
- Process metrics
Grafana is also used to review:
- Recent system errors
- Container logs
- Authentication events
- Reverse proxy logs
- Vaultwarden logs
- Grafana stack logs
- Gitea logs
- Wiki.js logs
Status: Operational
Purpose: Metrics collection and monitoring backend
Status: Operational
Purpose: Linux host metrics
Status: Operational
Purpose: Docker container resource metrics
Status: Operational
Purpose: Service availability monitoring
URL:
https://status.casko.dev
Status: Operational
Purpose: Server and infrastructure monitoring
URL:
https://monitor.casko.dev
Status: Operational
Purpose: Centralized log aggregation
Status: Operational
Purpose: Collection and forwarding of system and application logs
Status: Operational
Purpose: Real-time Docker container log viewer
URL:
https://logs.casko.dev
Status: Operational
Purpose: Self-hosted Git repository management
URL:
https://git.casko.dev
Status: Operational
Purpose: Technical documentation and knowledge-base platform
URL:
https://wiki.casko.dev
The wiki is used to document:
- Infrastructure architecture
- Service deployment
- Configuration
- Troubleshooting
- Security controls
- Recovery procedures
- Cloud integration
- Project milestones
Status: Operational
Purpose: Continuous Integration and Continuous Deployment
URL:
https://ci.casko.dev
Authentication:
Gitea OAuth
- Automated pipelines
- Git integration
- Container-based builds
- Automated testing
- Deployment automation
- Repository automation
- Woodpecker Server
- Woodpecker Agent
Pipeline Execution: Verified successfully
Status: Operational
Purpose: Central service dashboard
URL:
https://home.casko.dev
Status: Operational
Purpose: Self-hosted password management
URL:
https://vault.casko.dev
Authentication:
Authentik protected
Status: Operational
Purpose: Web-based file management
URL:
https://files.casko.dev
Status: Operational
Purpose: Networking, encoding, development, and troubleshooting utilities
URL:
https://tools.casko.dev
Authentication:
Authentik protected
Status: Operational
Purpose: Self-hosted PDF processing platform
URL:
https://pdf.casko.dev
Authentication:
Authentik protected
Status: Operational
¶ Domain Map
| Domain |
Service |
| auth.casko.dev |
Authentik |
| lab.casko.dev |
Portainer |
| proxy.casko.dev |
Nginx Proxy Manager |
| grafana.casko.dev |
Grafana |
| status.casko.dev |
Uptime Kuma |
| monitor.casko.dev |
Beszel |
| logs.casko.dev |
Dozzle |
| git.casko.dev |
Gitea |
| wiki.casko.dev |
Wiki.js |
| ci.casko.dev |
Woodpecker CI |
| home.casko.dev |
Dashy |
| vault.casko.dev |
Vaultwarden |
| files.casko.dev |
File Browser |
| tools.casko.dev |
IT-Tools |
| pdf.casko.dev |
Stirling PDF |
Implemented controls include:
- UFW firewall
- Default-deny inbound policy
- Minimal externally exposed ports
- HTTPS for web applications
- Reverse proxy architecture
- SSH key authentication
- Firewall logging
- Service exposure review
Public infrastructure identifiers such as server IP addresses are intentionally omitted from this documentation.
SSH access is hardened using:
- ED25519 keys
- Public-key authentication
- Password authentication disabled
- Root password login disabled
PermitRootLogin prohibit-password
PubkeyAuthentication yes
PasswordAuthentication no
- SSH brute-force protection
- Automatic IP banning
- Failed login detection
- User enumeration detection
Status: Operational
- CrowdSec Agent
- CrowdSec Firewall Bouncer
- SSH brute-force detection
- Slow brute-force detection
- User enumeration detection
- HTTP attack detection
- CVE probe detection
- Nginx threat detection
- Detection active
- Firewall bouncer connected
- Automated enforcement enabled
Status: Operational
Security visibility is provided through:
- Grafana
- Prometheus
- Loki
- Alloy
- Dozzle
- CrowdSec
- Fail2Ban
- Centralized application logs
- Linux host monitoring
- Docker container monitoring
- Firewall logging
This provides visibility across:
- Authentication activity
- Application errors
- Container behavior
- Resource utilization
- Network-related events
- Service availability
- Suspicious connection activity
A security notification was received from Hetzner regarding suspicious network activity associated with the ByteGeist VPS.
The notification required investigation to determine whether a service, container, exposed application, configuration issue, or other server activity could be responsible.
The investigation was treated as a security and infrastructure troubleshooting incident.
No claim is made that a full server compromise, malware infection, or specific attacker was conclusively identified.
The investigation focused on:
- Determining whether suspicious outbound activity was occurring
- Reviewing exposed network services
- Inspecting firewall configuration
- Reviewing Docker-hosted applications
- Looking for unnecessary or vulnerable services
- Increasing visibility into new outbound connections
- Reducing attack surface where practical
- Monitoring for recurrence
The troubleshooting process included reviewing:
- Running services
- Listening ports
- Docker containers
- Exposed Docker ports
- Reverse proxy configuration
- UFW configuration
- iptables rules
- Network connection behavior
- Authentication-related activity
- Security monitoring tools
- System and service logs
Particular attention was given to unexpected outbound SSH activity because the provider report involved network behavior that required further investigation.
Additional logging was introduced at the firewall level to provide visibility into new outbound SSH connection attempts.
An iptables rule was used to log new outbound TCP connections targeting SSH:
iptables -A OUTPUT \
-p tcp \
--dport 22 \
--tcp-flags FIN,SYN,RST,ACK SYN \
-m conntrack \
--ctstate NEW \
-j LOG \
--log-prefix "OUTBOUND SSH NEW: "
This rule does not block SSH traffic by itself.
Its purpose is to record new outbound SSH connection attempts so they can be correlated with:
- timestamps
- processes
- containers
- system activity
- provider reports
- additional log data
This improved visibility into traffic originating from the VPS.
The incident prompted a broader review of the server's security posture.
Areas reviewed included:
- Externally exposed ports
- Container configurations
- Reverse proxy configuration
- Authentication settings
- SSH configuration
- Firewall behavior
- Security monitoring
- Threat detection
- Logging coverage
- Running services
Existing protections such as CrowdSec, Fail2Ban, UFW, centralized logging, and key-only SSH access were incorporated into the investigation.
Follow-up actions included:
- Increasing firewall logging
- Monitoring outbound SSH connections
- Reviewing externally exposed services
- Reviewing Docker networking
- Auditing active services
- Confirming SSH authentication controls
- Confirming firewall protections
- Reviewing CrowdSec and Fail2Ban operation
- Improving security visibility
The goal was both to investigate the reported activity and to make future suspicious behavior easier to identify.
The incident provided hands-on experience with:
- Linux incident investigation
- Network troubleshooting
- Firewall analysis
- iptables
- UFW
- Connection-state tracking
- Docker security review
- Log analysis
- Attack-surface review
- Security hardening
- Provider communication
- Incident documentation
The investigation did not establish enough evidence to publicly claim a specific root cause or confirmed compromise.
This case study is therefore documented as an investigation and hardening exercise rather than as a confirmed intrusion.
ByteGeist performs scheduled local backups with short-term retention.
- Automated execution
- Daily schedule
- Rotating retention
- System and configuration backups
- Recovery-focused design
Status: Operational
Automated offsite backups from the Hetzner VPS to encrypted Amazon S3 storage.
- Automated backup creation
- AWS CLI upload
- Least-privilege IAM access
- Server-side encryption
- S3 versioning
- Lifecycle management
- Scheduled execution
- Backup status verification
Exact bucket names, account IDs, and internal paths are intentionally omitted from this public documentation.
Testing has included:
- Manual S3 upload tests
- Download tests
- Delete tests
- Manual backup execution
- SHA-256 checksum verification
- Archive readability tests
- Scheduled execution tests
- Cross-account migration integrity testing
- Live post-migration backup testing
Status: Operational
Backup validation is treated as a separate requirement from simply creating backup files.
Validation procedures include:
- Confirming archive creation
- Confirming successful cloud upload
- Checking archive readability
- Comparing object counts
- Verifying SHA-256 checksums
- Performing recovery-oriented tests
- Validating scheduled execution
Status: Recoverable
Disaster recovery documentation includes:
- Recovery procedures
- Service inventory
- DNS information
- Recovery priorities
- Restore procedures
- Validation procedures
- Backup locations
- Infrastructure dependencies
Exact credentials, cloud identifiers, IP addresses, and sensitive implementation details are intentionally excluded from public documentation.
Status: Documented
- Responded to a provider security/abuse notification involving suspicious network activity
- Reviewed Linux network and firewall configuration
- Inspected exposed services and Docker-hosted workloads
- Added outbound SSH connection logging using iptables and conntrack
- Reviewed UFW, CrowdSec, Fail2Ban, and existing security controls
- Increased monitoring and network visibility
- Performed additional security hardening
- Documented the incident without claiming an unverified root cause
- Consolidated ByteGeist cloud resources into a primary AWS environment
- Migrated approximately 2.7 GiB of encrypted backup data
- Used IAM, STS temporary credentials, cross-account S3 policies, and AWS CLI
- Recreated encrypted S3 storage
- Configured S3 Public Access Block
- Configured lifecycle policies
- Preserved backup versioning and retention behavior
- Created separate least-privilege backup identities
- Updated AWS CLI profiles and backup automation
- Verified object counts and storage totals
- Performed SHA-256 checksum validation
- Tested live backup execution
- Rebuilt multi-region CloudTrail
- Configured budget alerts
- Revoked obsolete credentials
- Removed temporary migration identities
- Retired obsolete cloud resources
Completed:
- AWS security baseline
- CloudTrail multi-region logging
- Encrypted S3 offsite backup storage
- Least-privilege IAM backup identity
- Automated Hetzner-to-S3 backups
- Restore verification
Deployed:
- Grafana
- Prometheus
- Node Exporter
- cAdvisor
- Operations dashboards
Deployed:
- Loki
- Alloy
- Centralized log dashboards
Deployed:
- Authentik
- OAuth2
- OpenID Connect
- Single Sign-On
- Two-Factor Authentication
Implemented:
- Password authentication disabled
- ED25519 key authentication
- Root password login disabled
- Key-only SSH access
Implemented:
- SSH monitoring
- Failed login detection
- Automatic IP banning
Implemented:
- CrowdSec agent
- Firewall bouncer
- Attack detection
- Automated enforcement
Implemented:
- Woodpecker Server
- Woodpecker Agent
- Gitea OAuth integration
- Automated pipeline execution
- Linux administration
- Docker container management
- Reverse proxy management
- SSL/TLS
- Monitoring
- Centralized logging
- Identity management
- Single Sign-On
- Two-Factor Authentication
- Backup automation
- AWS offsite backups
- Backup validation
- Disaster recovery documentation
- SSH hardening
- Fail2Ban
- CrowdSec
- CI/CD
- AWS integration
- Cloud audit logging
- Cloud cost controls
- Service documentation
- Security incident investigation
- Grafana alerting
- Security dashboard
- Portfolio development
- Database-aware backups
- Additional incident documentation
- Disaster recovery testing
- Vulnerability scanning
- Infrastructure as Code
- Terraform
- Automated service deployment
- Expanded security monitoring
- GitOps workflows
- Grafana alerting
- Database-aware backup improvements
- CrowdSec visualization/dashboard
- Document additional troubleshooting incidents
- Disaster recovery testing
- Vulnerability scanning
- Automated deployments
- Security monitoring improvements
- Infrastructure as Code
- Terraform
- GitOps workflows
- Automated environment rebuilds
ByteGeist provides hands-on experience with:
- Linux Administration
- Ubuntu Server
- Docker
- Docker Compose
- Networking
- Reverse Proxies
- SSL/TLS
- Monitoring
- Alerting
- Centralized Logging
- Identity Management
- OAuth2
- OpenID Connect
- Single Sign-On
- Two-Factor Authentication
- Threat Detection
- Intrusion Prevention
- Firewall Management
- iptables
- UFW
- Network Troubleshooting
- Security Incident Investigation
- Git Hosting
- CI/CD
- Backup & Recovery
- Disaster Recovery
- Security Hardening
- Technical Documentation
- Automation
- System Administration
- Hybrid Cloud Integration
- AWS
- Amazon S3
- IAM
- CloudTrail
- AWS CLI
- AWS Budgets
- Cross-Account AWS Migration
- Cloud Cost Management
- Observability
- Log Analysis
- Troubleshooting
| Capability |
Status |
| Linux Administration |
Operational |
| Docker |
Operational |
| Reverse Proxy |
Operational |
| SSL/TLS |
Operational |
| Identity Management |
Operational |
| Single Sign-On |
Operational |
| Two-Factor Authentication |
Operational |
| Monitoring |
Operational |
| Logging |
Operational |
| Security Hardening |
Operational |
| Threat Detection |
Operational |
| Firewall Management |
Operational |
| Incident Investigation |
Operational |
| Backup Automation |
Operational |
| Disaster Recovery Documentation |
Operational |
| Git Hosting |
Operational |
| CI/CD |
Operational |
| Offsite Backups |
Operational |
| AWS S3 |
Operational |
| AWS IAM |
Operational |
| AWS CloudTrail |
Operational |
| AWS Cost Controls |
Operational |
| Cross-Account Migration |
Completed |
| Hybrid Cloud Integration |
Operational |
| Documentation |
Current |
This wiki is intended to demonstrate infrastructure design, systems administration, cloud, security, troubleshooting, and documentation skills.
For security reasons, public documentation intentionally excludes or redacts:
- Public server IP addresses
- AWS account IDs
- Exact S3 bucket names
- Access keys
- Tokens
- Passwords
- Private keys
- Internal credentials
- Sensitive backup paths
- Provider-specific identifiers
- Other unnecessary infrastructure details
Technical architecture and implementation concepts remain documented wherever they can be shared safely.
ByteGeist demonstrates practical experience designing, deploying, securing, monitoring, documenting, and troubleshooting a self-hosted Linux infrastructure environment integrated with AWS.
The project includes:
- Linux server administration
- Containerized services
- Reverse proxy architecture
- Identity management
- Monitoring and observability
- Centralized logging
- Security hardening
- Threat detection
- Incident investigation
- Backup automation
- Disaster recovery
- AWS integration
- IAM
- S3
- CloudTrail
- CI/CD
- Technical documentation
The environment is continuously expanded as new systems administration, cloud, networking, and security concepts are learned and implemented.
Last Updated: September 14, 2026
Version: 2.0