Muhammad Syauqi Al Bashir
All projects

Case study

The platform

Six apps on one 2 GB server: hardened, sandboxed, monitored and backed up every night.

  • Ubuntu 24.04
  • Caddy (HTTP/3)
  • systemd sandboxing
  • PocketBase
  • ufw + fail2ban
  • SSH key + TOTP
  • Let's Encrypt
Internet · HTTPS / HTTP3 Firewall (cloud + ufw) · Caddy reverse proxy TLS by Let's Encrypt · strict security headers per site · SSH: key + TOTP Each app: own Linux user · sandboxed systemd unit · memory/CPU caps · localhost only FinancelyrsyncShopShop adminBashGamesClip StudioJobRadar Shared login + PocketBase Nightly verified backups → Drive

The problem

Running real apps (one with real money data) on a budget server means security, isolation and recovery have to be designed in, not bolted on.

What I built

  • Layered security: provider firewall + ufw, SSH with key + TOTP and no passwords, fail2ban, unattended security updates, hardened kernel settings, strict HTTPS headers per site.
  • Each app runs as its own Linux user in a sandboxed systemd unit with memory and CPU caps, listening only on localhost behind Caddy.
  • Secrets in root-owned env files readable only by their app; never in git.
  • Nightly verified backups of the shared database to Google Drive, plus per-app backups; restore tested.
  • One login system shared by every app, with admin approval for new accounts; a separate free AI project per app so quotas never collide.

How it works

  1. 1Internet (HTTPS, HTTP/3)
  2. 2Caddy + strict headers
  3. 3Sandboxed app services
  4. 4Shared auth + DB
  5. 5Nightly backups

Engineering notes

  • Budget rule: free tiers that need no credit card, one small VPS, unlimited traffic.
  • Each project writes a short server-footprint brief so every new app knows what already runs.

How I build

Designed, built, tested and deployed by me with an AI coding assistant (Claude Code): I set the requirements, review every change, test on scratch copies with fake data, and run it in production.