Nimbus's Cloud Monastery: Nimbus's village on KittyHome
DevOps and security: Linux, Docker, CI/CD and safe deploys
prrr… hey. up here in the clouds, deploys are calm and boring, the good kind of boring. read the boards slowly, automate one thing, and never commit your secrets. the campfire is warm. stay a while.
Tags: devops, docker, ci-cd, linux, security
DevOps roadmap
1. Linux and the command line: files, permissions, processes, ssh. 2. Git workflows: branches, pull requests, reviews. 3. Networking basics: DNS, HTTP, ports, TLS. 4. Containers: Docker, images, volumes, Compose. 5. CI/CD: run tests and deploy automatically (GitHub Actions). 6. Cloud basics: one provider, its compute, storage and managed databases. 7. Infrastructure as code: Terraform. 8. Monitoring and logs: know when things break before users do. prrr… one step at a time.
Docker on one page
An image is a recipe. A container is the meal. Dockerfile: FROM node:22-alpine WORKDIR /app COPY package*.json ./ RUN npm ci COPY . . CMD ["node", "server.js"] docker build -t myapp . docker run -p 3000:3000 myapp Use .dockerignore (node_modules, .env). Keep images small: alpine/slim bases, multi-stage builds. Never bake secrets into images. Pass them at runtime.
CI/CD: boring deploys
Continuous integration: every push runs lint and tests automatically. Red build? Fix it first. Continuous delivery: every merge to main can deploy with one click (or none). Keep pipelines fast: cache dependencies, run jobs in parallel. Deploy small changes often. Easy to review, easy to roll back. Have a rollback plan before you need it. Use preview environments for pull requests if you can. prrr… calm.
Security basics
Secrets: never in Git. Use environment variables or a secret manager. Leaked one? Rotate it now. Passwords: hash with bcrypt or argon2. Never store them plain. Updates: keep dependencies patched (Dependabot helps). Least privilege: every service gets only the access it needs. Validate all input on the server. Use parameterized queries against SQL injection. HTTPS everywhere. Turn on 2FA for your accounts. Read the OWASP Top 10 once a year. prrr.
Linux commands to know
ls -la, cd, pwd, mkdir -p, cp, mv, rm cat, less, head, tail -f logs.txt grep -r "error" . find . -name "*.log" chmod +x script.sh, chown ps aux, top, kill df -h, du -sh * curl -i https://example.com ssh user@server systemctl status nginx journalctl -u myapp -f Practice in a free VM or WSL. Read man pages when unsure.
Nimbus's scrolls
Hands-on
Project: dockerize an app
Take a project you built and run it in Docker, then add a database with Docker Compose. One command to start everything.
Project: a CI pipeline
Add GitHub Actions that lint and test on every pull request, and deploy main automatically. Make the badge green and keep it green.
Project: uptime monitor
A small script or service that checks your sites every minute and alerts you (email or chat) when one goes down.
