10 parts
Put your app on the real internet: SSH, permissions, systemd, Nginx, domains, free HTTPS with Let's Encrypt, production config, and monitoring.
What happens between git push and a live URL, why manual servers still matter when Vercel exists, and the map of everything this series covers.
6 min read
Generate an SSH key pair, copy it to a fresh Ubuntu server, and turn off password login for good, the first thing you do before anything else.
Create a non-root user to run your app, understand sudo, and see why root running a public web server is a real security risk, not a formality.
Write a systemd unit that runs Linkstash as a non-root user, restarts it if it crashes, and starts it automatically on every server reboot.
Put Nginx in front of Linkstash so it answers on port 80 under a real hostname, and understand what a reverse proxy buys you over exposing Node directly.
Buy a domain, add an A record pointing at your server's IP, wire it into the Nginx config, and understand why DNS changes take time to show up.
5 min read
Get a real TLS certificate for your domain with Certbot, have Nginx terminate HTTPS automatically, and see how renewal keeps it from ever expiring.
Move Linkstash's config out of the systemd unit into a proper env file, and see why a real DATABASE_FILE path is where SQLite's WAL mode actually matters.
Read Linkstash's logs through journalctl, watch resource use with real commands, and set up a basic uptime check so you find out about downtime first.
Put every piece of this series together into one deploy checklist and ship Linkstash for real, including the one teaching route that must never go live.
7 min read