Start here: the self-hosting learning path
The guided route from a freshly ordered server to a finished self-hosting stack – all Serverküche recipes in the right order.
Self-hosting looks like a huge mountain at first – but it’s really just a chain of small steps that build on each other. This path guides you through all the Serverküche recipes in the right order: from the first server setup, through hardening, to ready-to-serve applications. Every tutorial assumes exactly what you built in the previous one – you’ll never land on a page whose basics you’re still missing.
You don’t have to do everything in order: if you’re already further along, jump straight to the section you need. New here? Start at the top.
1 · Get the server ready
From the freshly ordered server to a properly set up base system.
- First steps with a netcup VPS Beginner · approx. 30 minutes
From a freshly ordered netcup server to a ready-to-use system: SSH login, system updates, a sudo user and the most important first steps.
- Hardening SSH access Beginner · approx. 20 minutes
Key-based login instead of passwords and no root login: the most important moves to harden the front door to your server.
- Connecting a domain to your server (DNS basics) Beginner · approx. 20 minutes
A and AAAA records, TTL and propagation explained clearly: how your own domain points to your server – the prerequisite for HTTPS with Traefik.
2 · Harden & back up
Firewalls, automatic updates, brute-force protection and real off-site backups.
- Setting up a firewall with UFW Beginner · approx. 15 minutes
Set up a host firewall in minutes with UFW: block everything except SSH, HTTP and HTTPS on your server – without ever locking yourself out.
- Setting up the netcup firewall in the SCP (with the stateless-UDP trick) Intermediate · approx. 25 minutes
Set up the netcup firewall as network protection in front of the server: composable policy templates in the SCP – with the trick for stateless UDP (DNS & NTP).
- unattended-upgrades: automatic security updates for Debian Beginner · approx. 20 minutes
Debian installs security updates automatically: set up unattended-upgrades, control the reboot, and verify it really runs.
- Setting up Fail2ban: block brute-force attacks automatically Intermediate · approx. 40 minutes
Fail2ban watches your logs and bans IPs after too many failed attempts – with a safe whitelist for your own address so you don't lock yourself out.
- netcup snapshots & the Server Control Panel (SCP) Beginner · approx. 15 minutes
Use the netcup Server Control Panel & snapshots properly: a safety net before risky changes – and why it's no substitute for a real backup.
- Restic backups: encrypted and off-site Intermediate · approx. 45 minutes
Off-site backups with Restic: set up encrypted, restore snapshots, prune with retention and automate via a systemd timer.
3 · The Docker foundation
Understand containers and make apps reachable with automatic HTTPS – the pattern every app reuses from here on.
- Installing Docker on Debian Beginner · approx. 15 minutes
Install Docker Engine and Docker Compose cleanly from the official repository – the foundation for most self-hosting recipes.
- Understanding Docker Compose: services, volumes, networks Intermediate · approx. 40 minutes
compose.yaml explained: services, volumes, networks and variables – the Docker vocabulary every app recipe in the Serverküche builds on.
- Setting up Traefik: reverse proxy with automatic HTTPS Intermediate · approx. 60 minutes
Traefik as a reverse proxy in front of your containers, with automatic Let's Encrypt certificates: every app gets a domain and HTTPS via a few labels.
4 · Your first applications
The services you self-host for – each one following the same Traefik recipe.
- Installing Uptime Kuma: server monitoring behind Traefik Intermediate · approx. 45 minutes
Set up Uptime Kuma behind Traefik and monitor your services: monitors, notifications and a status page – the first real app of the series.
- Vaultwarden: your own password manager behind Traefik Intermediate · approx. 45 minutes
Self-host Vaultwarden: a lean, Bitwarden-compatible password manager behind Traefik with HTTPS, an admin panel and an encrypted backup.
- Self-hosting Nextcloud: your own cloud behind Traefik Intermediate · approx. 60 minutes
Set up Nextcloud with Docker behind Traefik: your own cloud for files, calendar and contacts – with MariaDB, Redis and automatic HTTPS.
- Hardening & optimizing Nextcloud: clear every warning (part 2) Intermediate · approx. 45 minutes
Get your Nextcloud admin overview green: set up HSTS headers, email sending, enforced two-factor auth and brute-force protection with real IPs.
- Self-hosting Immich: your private photo backup behind Traefik Intermediate · approx. 60 minutes
Set up Immich with Docker behind Traefik: the self-hosted alternative to Google Photos – with automatic phone backup, face recognition and HTTPS.
- Self-hosting Paperless-ngx: the paperless office with OCR Intermediate · approx. 60 minutes
Set up Paperless-ngx with Docker behind Traefik: archive documents searchably via OCR – with full-text search, tags and automatic import.
- Self-hosting Jellyfin: your own media server behind Traefik Intermediate · approx. 60 minutes
Set up Jellyfin with Docker behind Traefik: stream your movies, series and music – with HTTPS and the library on netcup's Local Block Storage.
5 · Operations & pro moves
From tinkerer to operator: monitoring, modern attack defence, update discipline and private VPN access.
- Monitoring with Grafana & Prometheus: your server in live dashboards Advanced · approx. 60 minutes
A complete monitoring stack of Prometheus, node-exporter, cAdvisor and Grafana behind Traefik – with live metrics for host and containers.
- CrowdSec: modern, collaborative intrusion prevention Advanced · approx. 45 minutes
Set up CrowdSec with the Traefik bouncer: detect attacks from the access logs, block attackers with a 403 and benefit from the community blocklist.
Before the first recipe
No server yet? The server calculator estimates the RAM and CPU your planned services need, and the netcup recommendation explains the difference between VPS, VPS Lite and root server.