Linux system administration and support: server management, hardening and automation
Linux servers managed by people who work on them every day.
Linux system administration is the core of what we do: designing, configuring and keeping healthy the servers that run websites, applications and e-commerce. We don’t sell hosting as a sealed box - we work directly on your systems, document them and hand them back to you in a state you can actually understand. “We write the code and keep it running in production”: this page tells the second half of that sentence.
Need the first half instead - developing or evolving an application? Take a look at custom software development.
Overview
A well-managed Linux server doesn’t draw attention: it responds fast, updates without surprises, and when something breaks there’s a backup that actually restores. A badly managed one draws plenty of attention - usually at the worst possible moment.
The service covers the machine’s whole lifecycle: initial provisioning, hardening, planned updates, monitoring and intervention when something’s off. We work on bare-metal servers and virtual machines on any provider, either as one-off jobs - a problem to fix, a migration, an audit - or as ongoing management on a monthly retainer.
The method doesn’t change: standard configurations anyone can read, a single point of contact who genuinely knows your infrastructure, and reports that make sense even if you’re not a sysadmin. And what we configure stays yours: no proprietary panel, no artificial lock-in to us.
Typical problems we solve
- The server is slow and nobody knows why → we analyze load, I/O and configuration and remove the actual bottleneck, not the assumed one.
- The disk fills up and services stop → we set up log rotation, automatic cleanup and alerts that fire before things lock up.
- Updates have been frozen for years out of fear of breaking things → we schedule patches and distribution upgrades with a rollback plan ready to go.
- Backups exist but nobody has ever restored them → we make them encrypted, verified, with a restore procedure tested on a real machine.
- SSH exposed, permissions too broad, no firewall → we reduce the attack surface with hardening documented step by step.
- The previous provider vanished, taking the credentials with them → we run an audit, regain control of access and document everything.
- Every server is hand-configured and different from the rest → we bring the configuration into Ansible and make it reproducible.
What’s included
- Provisioning and installation: server setup from scratch - partitioning, users, services and the application stack (web server, PHP/Node.js, database, cache) - ready for production.
- Security hardening: key-only SSH access, firewalling, automatic security updates, fail2ban, correct permissions and an attack surface trimmed to what’s necessary.
- Updates and maintenance: regular system patching, planned distribution upgrades, log rotation and disk-space management.
- Automation: reproducible configurations with Ansible and idempotent scripts, so the environment can be rebuilt in minutes instead of days of manual work.
- Backups and recovery: encrypted backups tested periodically, with a restore plan we know how to run - not just configure.
- Monitoring and alerts: checks on resources, services and certificates, with notifications that arrive before your customers’ complaints do; on-call cover on a monthly retainer when downtime actually costs you.
Stack and technologies
We work daily with Debian and Ubuntu Server; on request we also manage AlmaLinux, Rocky Linux, Arch Linux and other distributions. On top runs the typical web production stack: Nginx or Apache, PHP-FPM, Node.js, MySQL/MariaDB or PostgreSQL, Redis for cache and sessions, Varnish where it earns its keep, Docker when containers genuinely simplify the deploy.
For automation we use Ansible; Terraform comes into play only where infrastructure complexity justifies it, never on principle. On the cloud side we work mainly with Google Cloud, alternatively AWS and DigitalOcean; on request also Azure, Hetzner and OVH. If you already have a stack, we adapt to it; if you’re starting from scratch, we pick the simplest solution that holds the load - and document it, so that a year from now anyone can understand why it’s built that way.
A real-world example
A web agency handed us about ten Ubuntu servers accumulated over years of projects: each configured by hand, different versions, updates lagging behind, and one night’s downtime caused by a disk saturated with logs. We started with an audit and an inventory of services and dependencies, then brought the configuration into Ansible: users, SSH hardening, firewalling, log rotation and automatic security updates, identical everywhere. The backups, which existed but had never been restored, are now encrypted and proven with a periodic restore on a test machine. Today a new server is ready in half an hour starting from the playbooks, alerts arrive before the clients do, and emergency work has become the exception: almost everything is planned, not scrambled.
Who it’s for
- SMEs and professional firms that want a reliable technical point of contact without setting up an in-house IT department.
- Web agencies and software houses that hand projects to clients and need solid servers behind the scenes.
- E-commerce and SaaS that can’t afford downtime in the moments that count.
- Anyone who’s inherited undocumented servers and wants to regain control before the next problem hits.
How we work
The first step is an audit: we take a snapshot of the systems’ state, flag the risks and propose a plan with clear priorities. Then we work in stages, without tearing down what already works, and leave every configuration documented: if you wanted to switch provider tomorrow, you could - and that’s exactly the guarantee that we’re doing good work today.
Standard coverage runs Monday to Friday, 10:00-18:00 , with priority triage: a P1 is picked up within one business hour (details are on the response times page). For pay-as-you-go work there are hour packages that never expire; quotes are always free, with a reply within one business day.
Frequently asked questions
Which Linux distributions do you work with?
Mostly Debian and Ubuntu, which we run in production every day; on request also AlmaLinux, Rocky Linux, Arch Linux and others. We handle both bare-metal servers and virtual machines on any cloud provider.
Do you take one-off jobs or only ongoing management?
Both. We can fix a specific problem - a migration, a slow server, a full disk - or manage your systems over time with a monthly retainer that includes monitoring, updates and verified backups.
Do you handle server security too?
Yes. SSH hardening, firewalling, security updates, fail2ban, permission management and configurations aligned with CIS best practices, all documented and verifiable.
Can you take over a server someone else already manages?
Yes. We run an initial audit, document the current state and propose a gradual handover plan, without tearing down what already works.
How much does Linux system administration cost?
We bill at a flat €75/hour. For recurring work, hour packages that never expire are more convenient: 5 hours at €350, 10 hours at €660, 20 hours at €1,200. Quotes are always free, with a reply within one business day.
How quickly do you respond if the server has a problem?
Standard coverage runs Monday to Friday, 10:00-18:00, with priority triage from P1 to P4: a P1 - production down - is picked up within one business hour. Out of hours we guarantee intervention only for P1 emergencies of clients with an active on-call plan; work planned at least 20 days ahead remains possible for everyone.
Do you also work at night or on weekends?
Guaranteed only for clients with an active on-call plan, and only for real P1 emergencies: production down, data loss, active security incident. On-call is a monthly retainer with limited seats, available on systems we manage and, after a case-by-case assessment, on others too: prices and rules are on the On-call page. Without a plan, coverage is Mon-Fri 10:00-18:00 and out-of-hours work is best effort: it may happen, but it is neither guaranteed nor something you can demand. Night or holiday work planned at least 20 days ahead remains available to everyone, at the surcharged rate.
Need a hand with your infrastructure?
Tell us the problem: we reply with a clear plan and a quote.
Get in touch →