Project: Secure Ubuntu Web Server
Combining SSH hardening, firewall configuration, and Nginx into one production-shaped build. · 20 min
Architecture: a single Ubuntu Server VM running Nginx, reachable only via hardened SSH for administration and via HTTP/HTTPS for public traffic — every other port closed by default. This project deliberately combines Levels 9 (SSH), 10 (Firewalls), and 14 (Web Servers) into one coherent build, which is exactly the shape a real "set up a web server" work ticket actually takes — no single level in isolation.
Requirements: a fresh Ubuntu Server 24.04 VM; a non-root administrative user with sudo access; an SSH key pair already generated. Implementation order matters here specifically to avoid locking yourself out: set up the administrative user and confirm sudo access first, confirm SSH key-based login works in a second session before touching sshd_config, harden SSH (disable root login and password auth), enable the firewall allowing only 22/80/443 (confirming SSH is allowed before enabling), then install and configure Nginx to serve a test site.
Verification: confirm SSH key login works and password login is rejected; confirm `ufw status` shows exactly the three intended ports; confirm the site loads over HTTP; confirm any other port (test with a throwaway service on an unlisted port) is unreachable from outside. Cleanup: if this was a genuinely temporary lab VM, destroy it once verification is complete rather than leaving an unused, unpatched server running indefinitely — an idle, forgotten VM is itself a real security liability.
- • Non-root admin user created with scoped sudo access (Level 4)
- • SSH key-based login confirmed working before hardening sshd (Level 9)
- • Root login and password auth disabled in sshd_config (Level 9)
- • Firewall enabled with only 22/80/443 allowed (Level 10)
- • Nginx installed and serving a test site (Level 14)
- • Verification: an unlisted test port confirmed unreachable from outside
Takeaway: This exact build — hardened SSH + minimal firewall + a web server — is close to the actual minimum viable configuration for any real internet-facing Linux server, not just a training exercise.