Synthetic Industry

Buyer collection · updated 2026-10-11

For a founder with one server and nobody who looks after it

Which fixed infrastructure jobs fit a founder running a VPS alone, in what order to consider them, and what you must hold yourself.

What your situation usually looks like

You started with one server because it was cheap and quick. It runs the product, perhaps in containers, perhaps by hand. You are the administrator by default. Nobody has written down how to rebuild it, who can log in, what is open to the internet or when it was last updated. This is normal and fixable, and none of it needs a full-time operations person. What it needs is a small number of specific things done in a sensible order and then checked.

  • You can log in, but you are not sure who else can.
  • You are not sure which ports are reachable from the internet.
  • You could not rebuild the server in a day from your notes.

Which job fits which worry

If the worry is access and exposure, the Linux baseline sets key-only SSH, a firewall and automatic security updates and proves each from outside. If the worry is that the app has no proper home, the Compose deployment gives it restarts, a health check and HTTPS. If logs keep filling the disk, rotation limits fix that at the source. If a process dies and nobody notices, supervising it with systemd restarts it and keeps its output. If you are afraid of your own env file, the secrets job moves values to protected files and hands you a rotation checklist. Each is a separate fixed price, published as a test price.

  • Access and exposure: the Linux baseline.
  • App with no proper home: the Compose deployment.
  • Disk filling or process dying: log rotation or the systemd service.

When to buy the bundle, and when not to

If three or more of those worries apply to the same server, the baseline project does them in a planned order so one change does not break the next, from a quoted price. If the server is old and the right answer is a new one, the move project does that with an inventory, a rehearsal and a way back. If only one thing is wrong, buy only that. After the work, a monthly patch and review keeps the server from drifting again; it is optional and has no emergency cover.

  • One worry: one fixed job.
  • Several worries on one server: the baseline project.
  • Old server that should be replaced: the move project.

What you keep

You keep the provider account, the domain, every private key and every secret value. You approve every change and, where a live step is needed, you either apply it from our change set or open a time-limited account and close it afterwards. We do not send anything to the server without your agreement, we do not promise uptime, and none of this is a security certificate. The first email needs only a description, never a login.

  • No passwords or keys in the first message.
  • Prices are untested and payment follows your sign-off.
  • These are new services with no delivery history to quote.

Sources and limits

  • Ubuntu Server: automatic updates Checked 2026-10-11.
    • Automatic updates are configured in two files, the default origins cover the security pocket, and automatic reboot is off by default.
  • Docker: use Compose in production Checked 2026-10-11.
    • Docker recommends removing bind mounts for application code, using a restart policy and recreating only the changed service.