← Zurück zu Projekte ← Back to projects PRJ.02

VPS — Eigene Server-Infrastruktur

ZeitraumTimeframe · seit August 2025since August 2025 RolleRole · Administration & BetriebAdministration & operations KontextContext · privates Infrastruktur-Projekt· personal infrastructure project

Seit August 2025 betreibe ich einen eigenen Root-Server, auf dem diese Website läuft — aber nicht nur sie. Der Server ist als kleines, wachsendes Homelab gedacht: mehrere Dienste laufen parallel auf derselben Maschine, sauber über eigene Apache-vHosts und Let's-Encrypt-Zertifikate voneinander getrennt.

Neben dem Webserver läuft eine selbst gehostete Nextcloud-Instanz für Dateien und Synchronisation. Damit ich nicht manuell nachsehen muss, ob alles funktioniert, meldet ein Discord-Bot laufend Aktivität aus dem System: neue SSH-Logins, von Fail2ban gesperrte IPs, verfügbare Paket-Updates, Speicherplatzstand und der Status der TLS-Zertifikate. Zusätzlich überwacht Uptime Kuma die Erreichbarkeit der einzelnen Dienste und schlägt Alarm, sobald etwas ausfällt.

Aufbau

Jeder Dienst bekommt seinen eigenen vHost und, wo nötig, eigene Systembenutzer bzw. Gruppen — die Website etwa läuft über eine eigene Gruppenberechtigung, damit Deploys ohne root-Zugriff möglich sind. Zugriff erfolgt ausschließlich per SSH-Key, Passwort-Login ist deaktiviert, und Fail2ban schützt zusätzlich vor Brute-Force-Versuchen.

Laufendes Projekt: Der Server ist bewusst als Homelab angelegt, das mit der Zeit wächst — es sollen mit der Zeit weitere selbst gehostete Dienste dazukommen.

Since August 2025 I've been running my own root server, which hosts this website — but not only that. The server is designed as a small, growing homelab: several services run in parallel on the same machine, cleanly separated through their own Apache vhosts and Let's Encrypt certificates.

Alongside the web server, a self-hosted Nextcloud instance handles files and sync. So I don't have to manually check whether everything's working, a Discord bot continuously reports activity from the system: new SSH logins, IPs banned by Fail2ban, available package updates, disk usage, and TLS certificate status. Uptime Kuma additionally monitors the reachability of each service and raises an alert as soon as something goes down.

Setup

Every service gets its own vhost and, where needed, its own system users or groups — the website, for example, runs under a dedicated group permission so deploys don't require root access. Access is SSH-key only, password login is disabled, and Fail2ban adds further protection against brute-force attempts.

Ongoing project: the server is deliberately set up as a homelab meant to grow over time — more self-hosted services are expected to be added.
LINUX APACHE NEXTCLOUD DISCORD BOT UPTIME KUMA FAIL2BAN