VPS — Eigene Server-Infrastruktur
Seit August 2025 betreibe ich einen eigenen Root-Server, auf dem diese Website läuft — aber nicht nur sie. Der Server ist als kleines, wachsendes Homelab gedacht: mehrere Dienste laufen parallel auf derselben Maschine, sauber über eigene Apache-vHosts und Let's-Encrypt-Zertifikate voneinander getrennt.
Neben dem Webserver läuft eine selbst gehostete Nextcloud-Instanz für Dateien und Synchronisation. Damit ich nicht manuell nachsehen muss, ob alles funktioniert, meldet ein Discord-Bot laufend Aktivität aus dem System: neue SSH-Logins, von Fail2ban gesperrte IPs, verfügbare Paket-Updates, Speicherplatzstand und der Status der TLS-Zertifikate. Zusätzlich überwacht Uptime Kuma die Erreichbarkeit der einzelnen Dienste und schlägt Alarm, sobald etwas ausfällt.
Aufbau
Jeder Dienst bekommt seinen eigenen vHost und, wo nötig, eigene Systembenutzer bzw. Gruppen — die Website etwa läuft über eine eigene Gruppenberechtigung, damit Deploys ohne root-Zugriff möglich sind. Zugriff erfolgt ausschließlich per SSH-Key, Passwort-Login ist deaktiviert, und Fail2ban schützt zusätzlich vor Brute-Force-Versuchen.
Since August 2025 I've been running my own root server, which hosts this website — but not only that. The server is designed as a small, growing homelab: several services run in parallel on the same machine, cleanly separated through their own Apache vhosts and Let's Encrypt certificates.
Alongside the web server, a self-hosted Nextcloud instance handles files and sync. So I don't have to manually check whether everything's working, a Discord bot continuously reports activity from the system: new SSH logins, IPs banned by Fail2ban, available package updates, disk usage, and TLS certificate status. Uptime Kuma additionally monitors the reachability of each service and raises an alert as soon as something goes down.
Setup
Every service gets its own vhost and, where needed, its own system users or groups — the website, for example, runs under a dedicated group permission so deploys don't require root access. Access is SSH-key only, password login is disabled, and Fail2ban adds further protection against brute-force attempts.