Services
Packages
Maintenance
Runtimes
Install DockerDocker Engine, Buildx and the Compose plugin from Docker's own repositories.Install Node.jsNode.js 24 or 22 from nodejs.org, checksum-verified, with optional global npm packages.Install PHPA PHP version with the extensions you choose and PHP-FPM, installed beside any existing PHP.Install ComposerThe current stable Composer from getcomposer.org, checksum-verified.Install PythonPython 3 from the distribution, with venv, pip and the headers extensions compile against.Install GunicornGunicorn, and the Uvicorn worker for ASGI apps, in an application's own virtual environment.Install Python Toolsuv, Poetry or Pipenv through pipx, with a compiler and the headers database drivers need.Configure Python AppA service account, Gunicorn settings and a hardened systemd service for one Python web app.Install KubernetesA Kubernetes node prepared with kubeadm, ready to join a cluster, or a new control plane.
Web servers
Install NginxNginx from the distribution's packages, enabled and running.Install CertbotCertbot from the server's repositories, ready to obtain Let's Encrypt certificates.Configure Reverse ProxyAn nginx site with a Let's Encrypt certificate that forwards requests to your app, API or container.Configure Certificate RenewalAutomatic certificate renewal twice a day, with nginx reloaded after each renewal.Check Certificate RenewalProve that certificates will renew by themselves, without changing anything.