Case study
The platform
Six apps on one 2 GB server: hardened, sandboxed, monitored and backed up every night.
- Ubuntu 24.04
- Caddy (HTTP/3)
- systemd sandboxing
- PocketBase
- ufw + fail2ban
- SSH key + TOTP
- Let's Encrypt
The problem
Running real apps (one with real money data) on a budget server means security, isolation and recovery have to be designed in, not bolted on.
What I built
- Layered security: provider firewall + ufw, SSH with key + TOTP and no passwords, fail2ban, unattended security updates, hardened kernel settings, strict HTTPS headers per site.
- Each app runs as its own Linux user in a sandboxed systemd unit with memory and CPU caps, listening only on localhost behind Caddy.
- Secrets in root-owned env files readable only by their app; never in git.
- Nightly verified backups of the shared database to Google Drive, plus per-app backups; restore tested.
- One login system shared by every app, with admin approval for new accounts; a separate free AI project per app so quotas never collide.
How it works
- 1Internet (HTTPS, HTTP/3)
- 2Caddy + strict headers
- 3Sandboxed app services
- 4Shared auth + DB
- 5Nightly backups
Engineering notes
- Budget rule: free tiers that need no credit card, one small VPS, unlimited traffic.
- Each project writes a short server-footprint brief so every new app knows what already runs.
How I build
Designed, built, tested and deployed by me with an AI coding assistant (Claude Code): I set the requirements, review every change, test on scratch copies with fake data, and run it in production.