Illia Nikitchenko

Infrastructure

Public services (this site) run on a small EU-based VPS: SSH keys only, firewall, automatic security updates, HTTPS. Hosting the public part outside my home network keeps the home network closed and costs less than running a server 24/7 at home.

Host

ComponentChoiceWhy
ProviderHetzner Cloud (Falkenstein, DE)EU-based, cheap, well documented
OSDebian 13 (stable)Predictable, matches the lab
AccessSSH keys, no root login, no password authRemoves password brute force entirely
Firewallufw + fail2banOnly 22, 80, 443 open to the internet
Updatesunattended-upgradesSecurity patches without manual work

Web server

Caddy serves the site and handles HTTPS automatically. It runs inside a Docker container rather than installed directly on the host โ€” the host stays free for lab experiments (new services, Docker networking tests, anything that might misbehave) without risking the live site. The container restarts on its own if it crashes. Redeploying the site means copying files into a folder the container reads from: no restart, no system-wide change.

ComponentChoiceWhy
RuntimeDockerIsolates the web server from host-level experiments
Web serverCaddy (official image)Automatic HTTPS, short config, well-maintained image
DomainOwn domain, A recordsnikitchenko.com and www both point straight at the VPS
TLSLet's Encrypt, issued by CaddyRenews on its own; certificates live in a Docker volume, so they survive container rebuilds

How the move into Docker went, including the certificate that wouldn't issue: Caddy in Docker.

Why not just run it at home?

The lab machine used to run WireGuard directly, with the home router forwarding a port to it. That setup worked but kept the home network reachable from the internet and cost real money to keep on 24/7. Moving the public-facing part to a cheap VPS closes that exposure and the lab now connects out to the VPS instead of being reached from the internet.

โ† Home