GUIDES
Technical guides
Practical guides on VPS, databases, integrations and dev tools - distilled from real deployment experience.
VPS
6 guidesSet up, secure and run a server: SSH, firewall, reverse proxy, CDN.
- 3 min read
Set up a new VPS: the essential secure steps
Bring up a fresh Ubuntu/Debian VPS safely: create a sudo user, log in with an SSH key, harden sshd, enable the UFW firewall, and disable ping.
- 5 min read
Set up Caddy as a reverse proxy on a VPS with Docker
Run Caddy as a Dockerized reverse proxy on a fresh VPS: create a shared network, write the Caddyfile and docker-compose file, get HTTPS automatically, then add new domains with a single zero-downtime reload.
- 5 min read
Automatic maintenance page with Caddy during Docker deploys
Use Caddy's handle_errors to catch the 502 Bad Gateway that appears while a container rebuilds and serve a static maintenance page automatically, with no manual on/off switch.
- 5 min read
Quick-check a VPS's specs with a single command
A one-line bash script that checks a VPS's OS, CPU, RAM, disk and network in about 15 seconds, plus reference tables that tell you whether each number is weak, fine or strong.
- 9 min read
Serve media via Cloudflare CDN + Backblaze B2 (free egress)
Put Cloudflare in front of a public Backblaze B2 bucket as a CDN to serve images, audio and video from a dedicated media subdomain: DNS, URL rewrite, CORS and cache rules, with free B2 egress.
- 6 min read
Where to put apps on a VPS: the /opt/apps directory layout
A simple convention for app code on a VPS: keep each app in its own folder under /opt/apps, chown the parent folder once, and git clone, git pull and .env edits never need sudo again.
Database
7 guidesInstall, connect securely, back up, migrate and tune PostgreSQL.
- 4 min read
Set up PostgreSQL on a VPS securely
Install and configure PostgreSQL on an Ubuntu/Debian VPS for production: create a database and user, open remote access safely (SSL + pg_hba + UFW), and understand transaction isolation.
- 2 min read
DBeaver tips: bigger toolbar icons and the TimeZone error fix
Two handy dbeaver.ini tweaks: scale up tiny toolbar icons on high-DPI displays with swt.autoScale, and fix the invalid value for parameter TimeZone Asia/Saigon error when connecting to PostgreSQL.
- 6 min read
Fix Docker containers that cannot reach PostgreSQL on a VPS
Docker picks a new network range every time you run docker-compose down and up, so PostgreSQL on the host rejects the container. Diagnose the subnet, open UFW and pg_hba.conf, then allow the whole 172.16.0.0/12 range to fix it once.
- 9 min read
Tune VPS performance: swap, PostgreSQL and the DB pool
Speed up a 16GB Ubuntu VPS that runs many Docker containers next to PostgreSQL: add swap to keep the OOM Killer away, tune PostgreSQL for more RAM and SSD storage, then raise the app's connection pool.
- 4 min read
Connect to PostgreSQL on a VPS through an SSH tunnel
Use an SSH tunnel so your dev machine can reach PostgreSQL on a VPS without exposing port 5432 to the internet, plus the DATABASE_URL setup for local and production.
- 4 min read
Clone a PostgreSQL database from a VPS to local Windows
Make a full copy (schema and data) of a PostgreSQL database on a VPS onto a Windows dev machine using an SSH tunnel, pg_dump and pg_restore, including how to move the local PostgreSQL port out of the way.
- 10 min read
Migrate a PostgreSQL database between two VPS with pg_dump
Move an entire PostgreSQL database (schema and data) from a source VPS to a target VPS through your local machine: dump with pg_dump, restore in a single transaction, verify row counts, then cut over and roll back safely.
Integrations
5 guidesWire up third-party services: email, payments, Google sign-in, Gemini.
- 6 min read
Send email with the Brevo API when your VPS blocks SMTP
Send verification emails from a VPS through the Brevo HTTP API v3 (HTTPS, port 443) instead of blocked SMTP ports: verify the sender and domain (DKIM, SPF), grab the right API key, configure .env, and fix common errors.
- 4 min read
Configure the SePay webhook and API key to accept payments
Collect the 4 environment variables you need from SePay.vn to accept bank-transfer payments with a static QR code (VietQR) and a webhook: add a bank account, create a webhook secured with an API key, and fix common issues.
- 3 min read
Configure Google OAuth for a new domain (Next.js and .NET API)
Create a new OAuth Client ID in Google Cloud Console for a new domain, declare the right JavaScript origins and redirect URIs, then update the environment variables of the Next.js frontend and the .NET API backend.
- 6 min read
Check and refresh the OG image cache on social platforms
Force Facebook, Messenger, Twitter/X, Telegram, Zalo and LinkedIn to re-scrape your Open Graph tags after a deploy so link previews show the new OG image, plus a standard meta tag checklist and fixes for images that do not show.
- 14 min read
Set up Vertex AI for the Gemini API (keyless and service account)
Set up Google Cloud Vertex AI (now Gemini Enterprise Agent Platform) to call Gemini models: enable the API, create a service account, authenticate keyless with ADC or with a JSON key, install the google-genai SDK, and fix org policy, 429 and 404 errors.
Dev tools
4 guidesTools and troubleshooting tips for day-to-day development.
- 2 min read
Roll back a Git commit and update safely on a VPS
Take your project back to an older commit, force push to the remote, then reset the VPS to match without a merge conflict, then rebuild the service and clear caches.
- 4 min read
Debug and bypass SSL pinning on an Android emulator
Inspect the API traffic of an Android app that uses SSL pinning with LDPlayer 9 and HTTP Toolkit: enable root, connect over ADB, auto-bypass SSL, and handle advanced protections.
- 3 min read
Fix Claude Code connection errors on Windows (ECONNREFUSED, Bun crash)
Fully resolve two common Claude Code errors on Windows - can't connect to the API (ECONNREFUSED) and a Bun crash (Internal assertion failure) - by removing the NPM build, clearing config caches, and installing the Native Stable build.
- 11 min read
A dedicated Chrome for chrome-devtools-mcp that can sign in
Set up a per-project Chrome profile for chrome-devtools-mcp (Claude Code, Cursor...) to drive: it can still sign in to Google/Cloudflare and keep the session, run several projects in parallel, and never touch your personal Chrome.