Linux VPS Production Deployment — 0 to Pro
A complete, progressive guide to taking a fresh Ubuntu 24.04 VPS and turning it into a secure, monitored, backed-up production server running a real Nuxt 4 + NestJS + PostgreSQL + Redis application, deployed automatically via CI/CD.
No prior Linux knowledge is assumed. Every command is explained. Every configuration file's location is given. Every chapter ends with a production checklist.
Who this is for
You can write application code but have never owned a server. Or you have deployed by hand a few times and want to know what "production-ready" actually means, as opposed to "it responds to a browser".
The reference stack
| Layer | Technology |
|---|---|
| Server OS | Ubuntu 24.04 LTS |
| Provider | Hetzner Cloud (concepts apply to any provider) |
| Firewall | UFW + provider cloud firewall |
| Intrusion prevention | fail2ban |
| Runtime | Node.js LTS via NVM, pnpm via Corepack |
| Frontend | Nuxt 4 + Vue 3 + TypeScript |
| Backend | NestJS + TypeScript + Prisma + Socket.IO |
| Database | PostgreSQL 16 |
| Cache / pub-sub | Redis 7 |
| Containers | Docker + Docker Compose |
| Reverse proxy | Nginx |
| Process manager | PM2 |
| TLS | Certbot + Let's Encrypt |
| CI/CD | GitHub Actions and GitLab CI |
The journey
Table of Contents
Foundations
| Level | Chapter | What you learn |
|---|---|---|
| 0 | Fundamental Concepts | VPS, Linux, processes, ports, IP, TCP/UDP, DNS, HTTP/HTTPS, reverse proxy |
| 1 | Creating & Connecting to a VPS | Provisioning, SSH, key pairs, ~/.ssh, debugging connections |
| 2 | Linux Basics for Developers | Filesystem layout, 30 essential commands, permissions, octal modes |
| 3 | Users, sudo & Permissions | Root vs sudo, deploy users, groups, least privilege |
Securing the Server
| Level | Chapter | What you learn |
|---|---|---|
| 4 | Initial Server Security | Full hardening checklist, SSH config, unattended upgrades |
| 5 | Firewall | UFW, inbound/outbound, which ports to never expose |
Application Runtime
| Level | Chapter | What you learn |
|---|---|---|
| 6 | NVM & Node.js | Node versions, LTS policy, pnpm via Corepack, non-interactive shells |
| 7 | Git & Repository Deployment | Deploy keys, branches, safe.directory, ownership |
| 8 | Environment Variables & Secrets | .env files, build-time vs runtime, GitHub/GitLab secrets, rotation |
Data Layer
| Level | Chapter | What you learn |
|---|---|---|
| 9 | PostgreSQL | Roles, databases, connection strings, pg_hba.conf, native vs Docker |
| 10 | Redis | Cache, sessions, queues, Socket.IO adapter, persistence, auth |
| 11 | Docker & Docker Compose | Images, containers, volumes, networks, production compose files |
Running in Production
| Level | Chapter | What you learn |
|---|---|---|
| 12 | Building the Application | Nuxt .output, NestJS dist, Prisma generate & migrate deploy |
| 13 | PM2 | Process management, cluster mode, ecosystem.config.cjs, startup |
| 14 | Nginx | Reverse proxy, server blocks, WebSocket upgrade, static caching |
| 15 | DNS | Records, TTL, propagation, dig debugging |
| 16 | SSL / HTTPS / Certbot | ACME, HTTP-01, renewal, TLS hardening |
Automation
| Level | Chapter | What you learn |
|---|---|---|
| 17 | CI/CD Concepts | Pipelines, gates, artifacts, rollback thinking |
| 18 | GitHub Actions | Full production workflow, line by line, plus every common error |
| 19 | GitLab CI & Runner | .gitlab-ci.yml, runner install, executors, comparison with Actions |
| 20 | Deployment Strategies | Simple, zero-downtime, blue-green, rolling, container-based |
Operations
| Level | Chapter | What you learn |
|---|---|---|
| 21 | Logging & Monitoring | journald, Nginx logs, PM2 logs, resource metrics, alerting |
| 22 | Backups | pg_dump, automation, 3-2-1, off-site, restore drills |
| 23 | Advanced Server Security | Threat scenarios with prevent/detect/recover playbooks |
Putting It Together
| Level | Chapter | What you learn |
|---|---|---|
| 24 | Production Architecture | The final design and what is public vs private |
| 25 | Complete From-Zero Deployment | One executable runbook, fresh VPS to live HTTPS app |
| 26 | Troubleshooting Handbook | 30 failures with causes, diagnostics, fixes, prevention |
| 27 | Production Checklists | New VPS, pre-production, post-deployment |
Reference
- Disaster Recovery Plan
- Cheat Sheets — commands, ports, directories, systemctl, Docker, Git, Nginx, PM2, PostgreSQL, UFW, SSH
Conventions used in this guide
Commands that run on your own laptop are marked:
# LOCAL
ssh deploy@203.0.113.10Commands that run on the server are marked:
# SERVER
sudo apt updateDANGEROUS COMMAND
Blocks like this precede any command that can destroy data or lock you out. Read them before pressing Enter.
PRODUCTION BEST PRACTICE
Blocks like this mark what experienced operators actually do.
COMMON MISTAKE
Blocks like this mark the traps that cost people a weekend.
Throughout, the example domain is example.com, the frontend lives at app.example.com, the API lives at api.example.com, and the server's public IP is 203.0.113.10 (a documentation-reserved address — replace it with yours).
"Working" vs "production-ready"
This distinction runs through the entire guide, so define it now.
| Working | Production-ready | |
|---|---|---|
| Process | Started with pnpm start in an SSH session | Managed by PM2/systemd, restarts on crash and reboot |
| Exposure | App on port 3000, open to the internet | Bound to 127.0.0.1, only Nginx reachable |
| TLS | None, or self-signed | Let's Encrypt with automatic renewal, verified |
| Secrets | Hard-coded or committed | Injected from .env with 600 perms, rotatable |
| Database | Default password, port open | Strong password, localhost-only, backed up nightly |
| Deploys | Manual SSH and git pull | Pipeline with lint, typecheck, build, migrate, reload |
| Failure | You find out from a user | You find out from an alert |
| Recovery | "I'll rebuild it" | Documented, tested restore under an hour |
Anything can be made to work in an afternoon. The rest of this guide is about the right-hand column.