secure-linux-web-hosting

bởi xixu-me

Sử dụng khi thiết lập, củng cố bảo mật hoặc kiểm tra máy chủ đám mây để tự lưu trữ, bao gồm DNS, SSH, tường lửa, Nginx, lưu trữ trang tĩnh, proxy ngược một ứng dụng, HTTPS với Let's Encrypt hoặc các ứng dụng khách ACME, chuyển hướng HTTP sang HTTPS an toàn hoặc tùy chọn điều chỉnh mạng sau khi triển khai như BBR.

npx skills add https://github.com/xixu-me/skills --skill secure-linux-web-hosting

Overview

Use this skill to turn a cloud server into a safely reachable web host without leaning on stale distro-specific memory or outdated Debian-10-era tutorials.

This skill keeps the familiar teaching arc of a beginner-friendly server guide, but turns it into a reusable operator workflow:

  1. Intake and routing
  2. Prerequisites
  3. Secure access
  4. Firewall and exposure
  5. Web server setup
  6. Static site or app proxy
  7. HTTPS
  8. Validation
  9. Optional advanced tuning

Before giving actionable commands, identify the distro family and verify the current package names, service units, config paths, and ACME-client guidance against official documentation for the user's distro and chosen tools.

Open references/workflow-map.md first for the phase sequence, then open the narrower reference file you need.

When to Use

Use this skill when the user mentions any of the following:

  • a cloud server, VM, droplet, or other Linux host they want to use for hosting
  • connecting a domain or DNS A/AAAA record to a server
  • SSH login, SSH hardening, root login, keys, ports, or firewall setup
  • installing or configuring Nginx for a website
  • serving a simple static site from Linux
  • putting a small app behind Nginx as a reverse proxy
  • HTTPS, Let's Encrypt, Certbot, acme.sh, certificate renewal, or redirecting HTTP to HTTPS
  • optional post-setup performance or network tuning such as BBR

Do not use this skill for:

  • Kubernetes, PaaS, or full container-orchestrator deployment design
  • application-specific build or CI/CD questions where Linux hosting is not the actual problem
  • Windows or macOS host administration
  • public multi-tenant production architecture reviews that need a broader SRE or platform-design treatment

Workflow

1. Intake and classify the current state

Start by identifying:

  • distro family or image name
  • whether the user has root access, an admin user, or only one live SSH session
  • whether DNS already points at the host
  • whether the goal is a static site or an app reverse proxy
  • whether ports are already exposed
  • whether HTTPS is already partially configured

If the distro is unknown, ask for it or have the user inspect /etc/os-release before giving concrete package or service commands.

2. Verify current docs before actionable commands

Use bundled references for routing, then verify details against live official docs before giving commands that depend on current distro behavior.

Always verify:

  • package manager commands and package names
  • firewall tooling and service names
  • SSH service unit names and config include paths
  • Nginx package and config layout
  • the chosen ACME client's current instructions

If you cannot verify a detail, say so and give high-level guidance instead of pretending the old Debian tutorial path is universal.

3. Keep the phases in order

Walk through the phases in this order unless the user is explicitly asking for review or remediation of an existing setup:

  1. prerequisites
  2. secure access
  3. firewall and exposure
  4. web server
  5. choose one hosting branch: static site or app proxy
  6. HTTPS
  7. validation
  8. optional advanced tuning

Do not collapse the static-site branch and reverse-proxy branch into one default answer. Pick the branch that matches the user's goal.

4. Enforce the safety gates

Treat these as hard stop checks:

  • Do not recommend changing SSH port, disabling password auth, or disabling root SSH login until key-based login works in a second SSH session.
  • Do not recommend certificate issuance until DNS resolves to the intended host and the HTTP site or proxy path works as expected.
  • Do not force an HTTP-to-HTTPS redirect until HTTPS loads cleanly.
  • Do not suggest BBR or similar tuning until secure hosting is already working.

Always distinguish:

  • local-machine actions: SSH, DNS checks, browser tests
  • server actions: package install, config edits, service reloads, firewall rules

Output Expectations

For a fresh setup, provide:

  • a brief diagnosis of the current state
  • the current phase and why it comes next
  • local-machine steps separate from server steps
  • concrete commands or config snippets only after doc verification
  • a verification step after each risky change
  • a short "if this fails, check X" branch for the likely mistake at that phase

For a hardening or troubleshooting review, provide:

  • the most likely risk or breakage first
  • a prioritized remediation sequence
  • the first safe verification step before the next config change

Common Mistakes

  • treating Debian-specific commands from an old article as Linux-universal
  • hardening SSH in the only active session and locking the user out
  • opening application ports directly instead of keeping the app on loopback
  • mixing static-file hosting guidance and reverse-proxy guidance in one config
  • attempting ACME issuance before DNS or HTTP is actually correct
  • forcing redirects before HTTPS is proven
  • treating BBR as part of the core setup instead of an optional later step
  • ignoring SELinux or AppArmor differences when Nginx can read files on one distro but not another

Reference Usage

Use references/workflow-map.md for the phase map, branching logic, and validation order.

Use references/distro-routing.md when distro family, package manager, firewall tooling, or config layout matters.

Use references/nginx-patterns.md when the user needs the static-site branch or the reverse-proxy branch.

Use references/security-and-tls.md for SSH hardening sequence, firewall posture, certificate issuance, renewal, and redirect timing.

Thêm skills từ xixu-me

github-actions-docs
xixu-me
Sử dụng khi người dùng hỏi cách viết, giải thích, tùy chỉnh, di chuyển, bảo mật hoặc khắc phục sự cố các luồng công việc GitHub Actions, cú pháp luồng công việc, trình kích hoạt, ma trận, trình chạy, luồng công việc tái sử dụng, tạo phẩm, bộ nhớ đệm, bí mật, OIDC, triển khai, hành động tùy chỉnh hoặc Bộ điều khiển Trình chạy Actions, đặc biệt khi họ cần tài liệu chính thức của GitHub, liên kết chính xác hoặc hướng dẫn YAML dựa trên tài liệu.
developmentdevopsdocument
use-my-browser
xixu-me
Sử dụng khi công việc phụ thuộc vào phiên trình duyệt trực tiếp của người dùng hoặc trạng thái hiển thị đã render thay vì các lệnh tĩnh, đặc biệt trong các ngữ cảnh gỡ lỗi trình duyệt hoặc các phần tử hoặc yêu cầu được chọn từ DevTools, bảng điều khiển đã đăng nhập hoặc luồng CMS, ứng dụng localhost, biểu mẫu, tải lên, tải xuống, kiểm tra phương tiện, kiểm tra DOM hoặc iframe, Shadow DOM, hoặc các lỗi trình duyệt trông giống như soft 404, tường xác thực, kiểm tra chống bot hoặc giới hạn tốc độ.
browser-automationweb-scrapingtesting
readme-i18n
xixu-me
Sử dụng khi người dùng muốn dịch README của kho lưu trữ, làm cho kho lưu trữ đa ngôn ngữ, bản địa hóa tài liệu, thêm bộ chuyển đổi ngôn ngữ, quốc tế hóa README, hoặc cập nhật các phiên bản README đã được bản địa hóa trong kho lưu trữ kiểu GitHub.
documentdevelopmentapi
openclaw-secure-linux-cloud
xixu-me
Sử dụng khi tự lưu trữ OpenClaw trên máy chủ đám mây, tăng cường bảo mật cho cổng OpenClaw từ xa, chọn giữa SSH tunneling, Tailscale hoặc reverse-proxy exposure, hoặc xem xét các thiết lập mặc định về Podman, ghép nối, sandboxing, xác thực token và quyền công cụ cho một triển khai cá nhân an toàn.
devopssecurity
develop-userscripts
xixu-me
Sử dụng khi xây dựng, gỡ lỗi, đóng gói hoặc xuất bản userscript trình duyệt cho Tampermonkey hoặc ScriptCat, bao gồm GM API, khối metadata, vấn đề quyền, thiết lập @match/@grant/@connect, script nền hoặc script theo lịch của ScriptCat, khối UserConfig hoặc quy trình đăng ký.
developmentbrowser-automationweb-scraping
opensource-guide-coach
xixu-me
Sử dụng khi người dùng muốn được hướng dẫn về cách bắt đầu, đóng góp, phát triển, quản trị, gây quỹ, bảo mật hoặc duy trì một dự án mã nguồn mở, hoặc hỏi về quy trình tiếp nhận người đóng góp, sức khỏe cộng đồng, kiệt sức của người bảo trì, quy tắc ứng xử, số liệu, vấn đề pháp lý cơ bản, hoặc việc áp dụng dự án mã nguồn mở.
developmentresearch
running-claude-code-via-litellm-copilot
xixu-me
Sử dụng khi định tuyến Claude Code qua proxy LiteLLM cục bộ đến GitHub Copilot, giảm chi tiêu trực tiếp cho Anthropic, cấu hình ghi đè ANTHROPIC_BASE_URL hoặc ANTHROPIC_MODEL, hoặc khắc phục sự cố thiết lập proxy Copilot như lỗi không tìm thấy mô hình, không có lưu lượng localhost, hoặc lỗi xác thực GitHub 401/403.
developmentapidevops
skills-cli
xixu-me
Use when users ask to discover, install, list, check, update, remove, back up, restore, sync, or initialize Agent Skills, mention `bunx skills`, `npx skills`, `skills.sh`, or `skills-lock.json`, ask "find a skill for X", or want help extending agent capabilities with installable skills.
developmentapiproductivity