Linux Server Management · Part of Your tech department

Linux servers set up, looked after and kept secure

The web server, the AWS account, the office box and the server in the cupboard nobody dares touch. We find out what you've got, tidy it up and keep it patched, monitored and backed up.

Rob Sherwood, co-founder of Dev Partners
Straight answer: we set up new Linux servers and take over existing ones, then keep them patched, monitored, backed up and secure. Backups are tested by actually restoring them every quarter, on AWS or on a box in your office.

It all still works. Mostly.

Somebody set the servers up years ago. Maybe a developer, maybe a previous IT company, maybe a keen member of staff who has since left. It all still works, mostly. Nobody is quite sure what's on it, when it was last updated or what would happen if it stopped.

Meanwhile there's a cloud bill every month that has crept up, and nobody can say what half of it is for.

That's usually where we start. Rob began his career in UNIX systems management, and we run our own Linux servers and our clients' every day, so very little in a server room surprises us any more.

Linux server management, in practice

New servers, or taking over old ones

We build new servers properly from the start. More often, we take over servers someone else built, work out what they do and bring them up to date without breaking anything.

Patching and security updates

Out-of-date operating systems and software are how most small firms get broken into. Security updates go on as routine, not when someone remembers.

Monitoring and alerts

Disk space, memory, uptime, certificates and failed jobs. If something is about to go wrong, we hear about it before your customers do.

Backups, tested by restoring them

Nightly database backups off the server, with an alert if one fails. Every quarter we restore something real somewhere safe, check it works and write down how long it took. More in our guide on how to test your backups.

Hardening and access control

SSH keys rather than passwords, access limited to the people and places that need it, firewalls set to let in only what should get in, and old accounts removed when people leave.

Moving off end-of-life systems

CentOS 7 and older Ubuntu releases no longer get free security updates. We plan the move to a supported system, test it and switch over out of hours.

What we actually run

Plenty of companies say they manage Linux servers. Here's what that means for us, day to day:

  • Ubuntu on most servers, and a steady stream of moves off CentOS 7, which reached end of life in June 2024.
  • AWS EC2 for most hosting, in accounts that belong to the client, plus physical boxes in offices where that makes more sense.
  • LXD containers to run several separate sites or systems on one host, each kept apart from the others.
  • Nightly database backups to Amazon S3, kept away from the server they came from, with an alert if a backup doesn't arrive.
  • Our own scanning tools, which check servers and code every night for passwords and keys left lying around and for unsafe database queries. We built them for our own systems first.
  • SSH access locked down to known locations and named keys, so a stolen password on its own gets nobody in.

We look after Windows servers too where a business has one, but Linux is where we're strongest, and where most web applications and business systems run.

How we take over a server nobody understands any more

  1. 1

    Make sure you own it

    The hosting account, the domain, the code and the logins should be in your name, not a former supplier's. We sort that first.

  2. 2

    Back it up before touching it

    A full copy goes somewhere safe before we change a thing, so whatever happens next can be undone.

  3. 3

    Find out what it does

    Every site, scheduled job, database and odd script, written down. There's nearly always one forgotten job that something depends on.

  4. 4

    Bring it up to date

    Patch it, lock it down, add monitoring and tested backups, and move it to a supported system if it needs one. Then it gets looked after like everything else.

A real one: the local professional services business whose developer moved on

A local professional services business came to us after their developer decided to concentrate on another side of his business. He had built and hosted everything for them: several web apps with a lot of complicated business logic behind them.

It had been built with every shiny tool going, Laravel Forge running the servers among them, and we had to get our heads round all of it before we were happy changing anything. So that's what we did first, one piece at a time.

It's all running and looked after now. We'll be honest, though: the PHP underneath is still older than we'd like. Upgrading it under several apps with that much logic is a job you plan properly rather than rush, so it's on the roadmap and we're working towards it.

If the person who built it has left, our guide on what to do when your developer leaves has the full checklist.

Security, and getting ready for Cyber Essentials

Most breaches at small firms come from the basics: old software, shared passwords and no two-factor login. We fix those first. Dev Partners is Cyber Essentials certified itself, so we know the process from the applicant's side. We find what would fail before the assessor does, fix it, and help you answer the questionnaire accurately. Our Cyber Essentials guide covers the questions that catch people out.

We use our own in-house scanning tools on our systems and our clients', and they catch a lot. But you shouldn't take the builder's word that the building is sound. We recommend an independent external penetration test, once a year for most businesses and every quarter if you hold a lot of sensitive data or a contract asks for it. We'll help you choose a tester, brief them and fix what they find.

We're not a 24-hour security operations centre, and we won't pretend to be. For most small businesses, that comes a long way after getting the basics right.

Cloud bills that make sense, and the box in the cupboard

AWS is very good at letting you start things and very bad at reminding you to stop them. Old test servers, oversized machines, storage nobody reads and backups of backups all add up. We go through the bill line by line, switch off what isn't needed, right-size what's left and keep an eye on it. We can't promise a figure until we've looked, but there's nearly always something.

On-site servers still have their place, especially for files and systems the office uses all day. We look after those the same way: patched, monitored and backed up somewhere other than the office.

Either way, the accounts are in your name and you pay the provider direct. We manage them but never hold them. If you leave, you get the logins, the documentation and a walk-through for whoever takes over.

Servers, software and the plan, as one arrangement

Linux server management is one part of Your tech department: one team that plans, builds, runs and secures your technology for one monthly fee, led by a fractional CTO.

What people ask us

Yes, that's most of what we do. We make sure the accounts are in your name, take a full backup, work out what the server does, then bring it up to date. Nothing gets changed until there's a copy to go back to.

We can. We look after AWS accounts for small businesses: security settings, updates, monitoring, backups and keeping the bill under control. The account stays in your name and you pay AWS direct.

Plan a move. CentOS 7 reached end of life in June 2024, so it no longer gets free security updates, and it will fail the Cyber Essentials requirement for supported software. We usually move servers to a current Ubuntu LTS release, test everything on the new server first, and switch over out of hours.

By restoring them. Every quarter we pick something real, such as a database or a whole site, restore it somewhere safe, check it works and write down how long it took. A backup job that says it succeeded is not the same as a backup you can restore from.

We check servers and code with our own in-house scanning tools, but we recommend an independent external penetration test as well: yearly for most businesses, quarterly where the data or a contract calls for it. We help you choose and brief a tester, and fix whatever they find.

Yes, where a business has one alongside its Linux servers. Linux is our strength and the headline here. If a setup is heavily Windows-based and needs a specialist, we will say so and help find one.

Looking after it is. The hosting or AWS bill itself is paid direct to the provider, so you always own the account and can see exactly what it costs.

Tell us about your servers

Tell us what you've got, even if you're not sure, and we'll tell you where we'd start.

Where the servers are, roughly what runs on them, and what worries you. If you don't know any of that, that's fine: finding out is the first job.

What we will cover:

  • What we'd check first
  • Whether anything is out of support
  • How your backups would be tested
  • How the monthly fee would be worked out

Rather talk now? Book a call or ring 01474 639 089.

We reply within one working day.

Get in touch