All Articles
Guides and opinion on dedicated servers, networking and running infrastructure, from the people who run ours.

AlmaLinux vs RHEL: When Is a Red Hat Subscription Worth It?
AlmaLinux gives you the RHEL platform (same ABI, same ten-year lifecycle, same ecosystem) for free. Red Hat charges four figures a year per server for the real thing. The interesting question isn't which is cheaper; it's what, precisely, the subscription buys and who actually needs those things. This guide itemises the answer: support SLAs, ISV certifications, live patching and lifecycle add-ons on one side; Alma's genuine independence perks (including drivers Red Hat dropped) on the other, plus the free 16-system Red Hat option most people forget exists.
Linux
Read more

Amsterdam Data Centres and Grid Congestion: Timeline and Sources, 2019 to 2026
Two separate limits apply to new data centres in the Amsterdam area. Planning law decides where one may be built and how much power it may add, and Amsterdam, Haarlemmermeer and the national government each set their own rules. Grid capacity decides whether TenneT and Liander can connect it, and in most of Noord-Holland they have no room for new large users. A project needs both a planning consent and a grid connection, so either limit can stop it. Those rules come from the two municipalities, the national government, the grid operators, the Netherlands Authority for Consumers and Markets (ACM) and the courts, and date from July 2019 to August 2026.
Infrastructure
Read more

What Amsterdam's Full Power Grid Means for Servers Hosted There
Most of the electricity grid in Noord-Holland is full for new or larger connections from big users, and Amsterdam has stopped new data centres, and expansions of existing ones, until 2035. Servers already running in Amsterdam keep their power. The shortage is in new capacity: another building, a bigger grid connection, or a denser rack in an existing hall.
Infrastructure
Read more

How to Capture and Analyse a DDoS Attack with Wireshark (and tcpdump)
When your server is under attack, "we're being DDoSed" is not actionable; "SYN flood, four million packets per second, spoofed sources, targeting port 443" is. The difference between the two is a thirty-second packet capture and a structured look at it. This guide covers capturing safely on a machine that's already saturated (tcpdump, not the Wireshark GUI), the triage workflow in Wireshark (Protocol Hierarchy, Conversations, I/O Graphs) and the display-filter signatures of the common attack vectors, ending with how to turn findings into mitigation.
Security
Read more

Bare Metal vs Dedicated Server: What the Two Terms Actually Mean
Bare metal and dedicated server describe the same thing: one physical machine, rented whole, with no hypervisor and no other tenant on it. The confusion is not about the hardware. It is about which era of hosting vocabulary a provider is using, and that vocabulary tends to predict how the machine is sold to you: by ticket or by API, by the month or by the hour. This guide explains where each term came from, lays out the operating-model differences a provider's word choice usually signals, gives you five questions to ask before you order, and covers the one case where neither term is what you actually want.
Infrastructure
Read more

Building a Flexible Router/VPN Backbone with VyOS, From Scratch to VPS Edition
Networking can feel intimidating at first, but with the right approach you can turn a simple virtual server into a capable routing backbone that spans from your home lab to a cloud VPS. This guide walks through building such a topology using VyOS. By the end you will have a home router, a public VPS router, a secure tunnel between them, and routing for multiple internal subnets.
Networking
Read more

CentOS Alternatives in 2026: AlmaLinux vs Rocky Linux (and How to Migrate)
CentOS Linux is gone (CentOS 8 reached end of life at the end of 2021 and CentOS 7 followed in mid-2024), and CentOS Stream is not a like-for-like replacement. The two real successors are AlmaLinux and Rocky Linux, and since 2023 they no longer work the same way under the hood: AlmaLinux targets ABI compatibility with RHEL, Rocky holds 1:1 binary parity. This guide explains what actually differs between them now, gives a conditions-based verdict instead of "it depends," and walks the real migration paths (migrate2rocky, almalinux-deploy, and ELevate for the CentOS 7 cross-major jump), including the pre-flight checklist, the inhibitor wall, and the rollback plan.
Linux
Read more

DDoS Attacks Explained: Common Forms and How to Protect Against Them
DDoS attacks come in three broad families: volumetric floods that saturate your pipe, protocol attacks that exhaust connection state, and application-layer floods that look like legitimate traffic. Each one exhausts a different resource, so each one needs a different defence, and no single layer stops all three. This guide maps the common attack forms to the resource they target and the mitigation that actually works against them, explains what an on-host firewall can and cannot stop, and ends with a practical incident-response runbook for when your server is under fire.
Security
Read more

How Much Server Do You Need? Sizing CPU, RAM and Storage by Workload
Most server sizing goes wrong in one of two directions: paying for cores that idle at 3% for a year, or discovering at launch that the database's hot set doesn't fit in RAM. Both mistakes come from skipping the same step: sizing from the workload instead of from a price list. This guide gives you the method (baseline, headroom, growth), the per-workload heuristics for CPU, RAM, storage and bandwidth, and the honest answer to when you should scale up versus out.
Hardware
Read more

Sensible Default Firewall Rules for a Linux Server
A fresh Linux server ships with no firewall rules at all. Every listener you start is instantly reachable from the whole internet. The fix is a short, well-understood baseline: default-deny inbound, allow established traffic, and an explicit allow-list for the services you actually run. This guide builds that baseline in nftables rule by rule, explains the parts everyone gets wrong (ICMP and IPv6), shows the same policy in ufw and firewalld, and covers how not to lock yourself out, plus the Docker port-publishing trap.
Security
Read more

Game Server Hosting on Bare Metal: Why Dedicated Hardware Wins
A game server is a single-threaded simulation loop on a fixed clock, so it lives or dies on per-core speed and steady timing, not core count. A shared VPS puts a hypervisor's scheduler between that loop and the CPU, and the jitter shows up as missed ticks. Bare metal removes the layer. This pillar covers bare metal against a VPS and managed game panels, why clocks beat cores, real RAM figures for Minecraft, Rust, ARK, Palworld, Valheim and CS2, storage and DDoS reality, running Pterodactyl or its Pelican fork yourself, and the honest cases where a VPS is still the right call.
Game Servers
Read more

Why Latency Matters for Game Servers and Player Experience
Ping is only part of what a player feels. A single round trip runs through input sampling, the last mile, transit and peering, a queue on the server, and the wait for the next simulation tick before the world reacts at all. This guide breaks down where felt delay actually comes from, how tick rate and netcode change the picture, why jitter and packet loss hurt more than a stable higher ping, and the one lever a host controls most: putting the server close to players on hardware that holds its tick rate.
Game Servers
Read more

Game Server Performance: Bare Metal vs Virtual Machines
Bare metal wins on the two numbers that decide whether a game server feels good: worst-case tick time and worst-case latency. A single-tenant VM on hardware you control gets close. An oversold multi-tenant VPS is where fixed-tick simulation falls apart, because a vCPU scheduled a few milliseconds late is a missed tick every player sees as rubber-banding. This guide covers what a hypervisor adds to a tick loop, why the 95th-percentile tick time matters more than average throughput, how to measure steal time and MSPT on your own server, and when a VM is still the right call.
Game Servers
Read more

How to Host a Minecraft Server on a Linux VPS or Dedicated Server
Hosting your own Minecraft server means the world your friends play in runs on hardware you control: no slot caps, no plugin restrictions, no per-player pricing. On a Linux VPS or dedicated server the path runs from sizing the machine and choosing between vanilla, Paper, Fabric and NeoForge to installing Java 25 and writing a systemd unit that survives reboots. After that come JVM sizing with Aikar's flags, the firewall rule and SRV record that let players in, whitelisting, backups, safe updating, and Bedrock crossplay through Geyser and Floodgate.
Game Servers
Read more

How to Host a Palworld Dedicated Server on Linux
A Palworld dedicated server holds up to 32 players in one persistent world, against four in a co-op session, and the world keeps running when the host logs off. Pocketpair ships the server for Linux as a free SteamCMD download, and since version 1.0 left early access on 10 July 2026 its documentation has changed in ways older guides miss: the multithreading flags every tutorial copies are no longer recommended, and RCON is deprecated in favour of a REST API. On Ubuntu or Debian the setup runs from Pocketpair's own hardware requirements through the install, PalWorldSettings.ini and a systemd unit that saves the world before it stops, to the one port players need, crossplay for Xbox and PS5, backups and updates. Server-side mods are the one thing a Linux server cannot run.
Game Servers
Read more

How to Host a Valheim Dedicated Server on Linux
A Valheim dedicated server keeps your world online when the friend who hosts it logs off, and it holds the game's full ten players without one of them carrying the whole simulation on a gaming PC. Iron Gate ships the server as a free SteamCMD download with a native Linux build. Valheim left early access with version 1.0 on 9 September 2026, and the release changed the save format: a world is now a folder of chunks instead of a .db and .fwl pair. On Ubuntu or Debian the server needs SteamCMD, three libraries, a systemd unit that stops it with SIGINT so it saves, and either three open UDP ports or Iron Gate's crossplay relay. Admin and ban lists, off-machine backups and BepInEx mods complete the setup.
Game Servers
Read more

How to Set Up Your Own Proxmox VE Server
You have a bare-metal box and you want it to run virtual machines and containers instead of a single operating system. Proxmox VE turns that raw hardware into a full virtualisation platform: a Debian-based host with a web UI, KVM full virtualisation, LXC system containers, built-in storage and networking, and no per-socket hypervisor licence to buy. This guide walks the whole path from a blank server to a working host. We install Proxmox VE 9.2 from the ISO, fix the APT repositories and update, understand the default bridge networking, look at storage, build a first VM and a first LXC container, and finish with basic hardening. By the end you will have a production-ready single node you can grow into a cluster later.
Virtualization
Read more

iptables vs nftables: What Changed and How to Migrate
If your server runs a current Debian, Ubuntu, or RHEL-family distro, your "iptables" rules are almost certainly already executing inside nftables. The iptables command has been a compatibility shim since 2019. The real question isn't which one wins; it's whether to keep writing rules in a legacy syntax on top of the new engine. This guide covers what actually changed architecturally, a side-by-side syntax comparison, what the honest performance data says, and a migration path that won't break Docker or lock you out.
Security
Read more

Jellyfin vs Plex vs Emby: Which Media Server Should You Self-Host?
The three big media servers used to differ mainly in polish. After Plex's 2025–2026 pricing changes (remote streaming behind a paywall, the lifetime pass at $749.99) the differences are now philosophical: fully free and open, freemium-with-account, or quietly commercial. This comparison lays out what's actually paywalled where, the remote-access and privacy models, honest transcoding hardware guidance for server deployments, and a verdict by user type.
Self-Hosting
Read more

Linux Dedicated Servers: How to Choose the Right Distribution
A Linux dedicated server gives you a whole physical machine with no hypervisor in the way, but which distribution should you run on it? Ubuntu, Debian, the CentOS successors, and RHEL each make different trade-offs around release cadence, support, and cost. This guide explains what a bare-metal Linux server actually is, when it beats a VPS or cloud instance, and how to pick a distribution by workload and support needs, with a side-by-side comparison and links to the right server for each.
Linux
Read more

First Hour on a New Linux Dedicated Server: A Hardening Checklist
A freshly provisioned server starts receiving SSH probes within minutes of its IP going live; honeypot studies show most exposed machines are attacked within a day. The good news: the defences that matter are a short, boring, one-hour checklist, not a security research project. This guide walks the eight steps in order (users and SSH keys, firewall baseline, automatic updates, fail2ban, time sync, a listener audit, and logging) with the exact commands for Debian/Ubuntu and the RHEL family, plus an honest list of what not to waste your first hour on.
Linux
Read more

Netplan Crash Course for Ubuntu Dedicated Servers
Netplan is the YAML layer that configures networking on Ubuntu Server: you describe addresses, routes and DNS in one file, and a generator renders that into config for systemd-networkd. This crash course is written for a dedicated box with a static public IP, no Wi-Fi, and SSH as the only way in. It covers where the files live, the root-only 600 permission rule, a full static IPv4 and IPv6 example, the generate, try and apply commands that stop you locking yourself out, plus VLANs, bonds, bridges, and the cloud-init file that keeps overwriting people's edits.
Linux
Read more

NetworkManager Crash Course: nmcli and Keyfiles for RHEL Servers
NetworkManager is the daemon that configures the network on every RHEL-family server, and since RHEL dropped the old network-scripts it is the only supported way to do it. This crash course runs it the way a dedicated server uses it: headless, static, over SSH, with nmcli and keyfiles instead of a desktop applet. You will learn the device-and-profile model that clears up most nmcli confusion, a full static IPv4 and IPv6 setup you can paste and adapt, where profiles live on disk across RHEL 8, 9, and 10, and how to change the network on a remote box without locking yourself out.
Linux
Read more

NinjaTrader VPS vs Dedicated Server: Which Is Faster for Futures Trading?
Three separate latencies sit between a futures platform and a matching engine, and only one of them is a hosting decision. This guide separates them, then gives the figures we measured from our own Chicago facility to the broker gateways a NinjaTrader or Tradovate setup actually connects to: 0.2 ms to Rithmic's market-data gateway, under 1 ms to its order gateway, about 3 ms to CQG's. The question that follows is not really "VPS or dedicated". Both sit in the same city and cover the same distance, so neither is closer to anything. What changes is who else is scheduling the CPU while your strategy is trying to finish a calculation, which is a question about load, not about milliseconds on a map.
Infrastructure
Read more

Running OPNsense as a Firewall VM on Proxmox
A virtualised OPNsense firewall on your Proxmox host gets you what appliance vendors charge four figures for: a full-featured firewall/router guarding your VMs, with snapshots before every upgrade and no extra hardware. The catch is that the setup details (bridges, VirtIO, offloading) decide whether it's rock-solid or mysteriously flaky. This guide covers the network designs that work on a dedicated server, the exact VM configuration the community has converged on, the install, and the honest caveats about performance and protecting the Proxmox host itself.
Networking
Read more

Proxmox Backup Strategies: Snapshots, vzdump and Proxmox Backup Server
Proxmox VE ships everything you need to never lose a VM, and the defaults use almost none of it. Snapshots that live on the same disk as the VM, one-off vzdump archives with no retention plan, and no restore testing is how virtualisation hosts actually get hurt. This guide builds the real strategy in three tiers: what snapshots are actually for, scheduled vzdump done properly (modes, retention, fleecing), and when Proxmox Backup Server's deduplication, verification, and offsite sync become worth a second box.
Virtualization
Read more

Building a Proxmox Cluster with High Availability on Dedicated Servers
A Proxmox cluster's honest requirements fit in one sentence: three nodes, a low-latency private link between them, and storage the surviving nodes can reach. Everything else (quorum, fencing, Ceph versus replication) is the reasoning behind those three. This guide covers what clustering gives you before HA even enters the picture, why quorum makes three the magic number, the corosync network rules people violate first, the three storage strategies, and what a failover actually looks like when a node dies at 3 a.m.
Virtualization
Read more

LXC Containers vs KVM VMs in Proxmox: When to Use Which
Proxmox VE gives you two ways to slice a server: full virtual machines via KVM, and LXC system containers that share the host's kernel. The right choice per workload is usually clear once you know the three questions that decide it: isolation, kernel, and migration. This guide explains how each actually works, compares them on the dimensions that matter operationally, settles the Docker question with Proxmox's own current guidance, and ends with a decision table you can apply per service.
Virtualization
Read more

What Is Proxmox VE? Choosing a Bare-Metal Hypervisor
Proxmox VE is a free, open-source virtualisation platform that runs directly on a physical server, turning one machine into a host for full virtual machines and lightweight containers. But it is not the only bare-metal hypervisor: VMware ESXi, XCP-ng, and Hyper-V all solve the same problem differently, and the right choice depends far more on licensing, clustering, and your team's ecosystem than on raw features. This guide explains what Proxmox VE actually is, what a bare-metal hypervisor means, and how the four main contenders compare on cost, management, high availability, storage, and backup, with a side-by-side table, an opinionated decision framework, and links to the right server to deploy it on.
Virtualization
Read more

Proxmox VE Networking Explained: Bridges, Bonds and VLANs
Networking is where most new Proxmox installations stall: the install works, the first VM boots, and then "how do I give it an IP?" turns into an afternoon of half-matching forum threads. The underlying model is actually small: VMs plug into Linux bridges, and everything else is variations. This guide builds that model properly: what vmbr0 really is, bridged versus routed versus NAT setups on a hosting provider, VLAN-aware bridges, bonding done right, where the SDN layer fits, and how to change any of it without cutting yourself off.
Virtualization
Read more

Proxmox VE vs VMware ESXi in 2026: The Dedicated-Server Operator's View
Almost every Proxmox-vs-ESXi comparison is written for a homelab or by a backup vendor. This one is written for the person renting a dedicated server or running a small hosting fleet, where the constraints are IPMI-only recovery, single-tenant hardware, no SAN, and network configured at the host. It covers what the Broadcom licensing shift actually changed, what the reintroduced free ESXi can and cannot do, the bare-metal architecture differences that matter, the multi-node failure modes that bite in production (and their fixes), honest per-node cost math, and where ESXi still wins.
Virtualization
Read more

Proxmox VE vs XCP-ng: Choosing an Open-Source Hypervisor
Post-VMware shortlists usually come down to these two: Proxmox VE, the Debian/KVM platform with everything integrated, and XCP-ng, the Xen-based XenServer descendant managed through Xen Orchestra. Both are genuinely production-grade and genuinely free; they just embody different philosophies about how a virtualisation platform should be built. This comparison covers the architectural split (KVM-in-Linux vs Xen-plus-dom0), the very different management and support models, storage and backup stories, current pricing on both sides, and a conditions-based verdict.
Virtualization
Read more

RAID Levels for Dedicated Servers: 0, 1, 5, 10 and ZFS Explained
RAID decides two things about your server before it ever boots: how much of the storage you're paying for is usable, and what happens at the moment a drive dies. Neither decision is reversible without rebuilding the array, so it's worth getting right at order time. This guide explains the four levels that matter in practice (0, 1, 5, and 10) plus ZFS's take on the same ideas, with honest guidance on rebuild risk, what RAID does not protect against, and which level fits which workload.
Linux
Read more

Secure Site-to-Site VPN with WireGuard on VyOS 1.5 for Inter-Site Connectivity
Connecting multiple office sites or datacenters securely and efficiently is a critical challenge for modern businesses. Traditional VPN solutions like IPsec or OpenVPN can be complex to configure and maintain, especially in multi-site environments. WireGuard offers a lightweight, fast alternative that's easier to set up. VyOS 1.5 fully supports WireGuard, making it an excellent choice for organizations looking to interconnect multiple datacenters or sites. In this guide, we'll show you how to set up a site-to-site WireGuard tunnel on VyOS 1.5. We'll cover routing, firewall configuration, and best practices. By the end, your sites will be securely connected over the internet with traffic routed effectively between LANs.
Networking
Read more

Self-Hosting Headscale on a Dedicated Server: Step-by-Step
Headscale gives you the half of Tailscale that isn't open source: the coordination server. Run it yourself and the official Tailscale clients (with their excellent NAT traversal and platform support) connect to infrastructure you control, with no per-user pricing and no third party holding your network's keys. This guide is the practical walkthrough: install from the official packages, TLS done the simple way, users and ACLs, the embedded DERP relay on your own network, and the honest operational limits of a deliberately small project.
Networking
Read more

Ubuntu Server in 2026: Choosing Between LTS Releases (and Upgrading)
Three Ubuntu LTS releases are in service right now: 22.04 approaching the end of standard support, 24.04 in its comfortable middle years, and the new 26.04 "Resolute Raccoon" with Linux 7.0. Which one belongs on your server depends on where you are in the cycle, and the answer is different for new deploys and existing fleets. This guide gives the support-window table, what actually changed in 26.04 for server operators, the honest reasons to stay on 24.04 for now, and the upgrade mechanics, including when the LTS-to-LTS path opens after 26.04.1.
Linux
Read more

Ubuntu vs Debian for a Dedicated Server: How to Choose
Ubuntu is built from Debian, so this is a comparison between close relatives: same package format, same init system, largely the same administration. The real differences are cadence, support windows, kernel freshness, and who stands behind the updates: a fixed two-year LTS rhythm with optional paid coverage to 2036, versus a community release that's done when it's done and free forever. This guide lays out what the two actually share, where they genuinely differ, and which server workloads favour which, with current versions and support dates, not folklore.
Linux
Read more

How to Upgrade Debian 12 to Debian 13 on a Production Server
Debian 12 "bookworm" quietly crossed a line in June 2026: regular security support ended, and it now runs on LTS. Debian 13 "trixie" has meanwhile matured through seven point releases, which makes this the right moment to do the in-place upgrade. This guide covers the full procedure for a remote production server: the pre-flight checklist (including the interface-renaming trap that can cut a remote box off mid-upgrade), the three-command upgrade itself, and the trixie-specific changes to check afterwards: /tmp on tmpfs, the sysctl move, and OpenSSH 10.
Linux
Read more

Windows Dedicated Servers: How to Choose the Right Version
A Windows dedicated server gives you a whole physical machine running Windows Server directly on the hardware, but which version and edition should you run on it? Windows Server 2019, 2022, and 2025 sit at different points on the support timeline, and Standard versus Datacenter changes what you can do with virtualisation. This guide explains what a bare-metal Windows server actually is, when it beats a VPS or cloud instance, and how to pick a version and edition by workload, support window, and licensing, with a side-by-side comparison and links to the right server.
Windows
Read more

WireGuard vs Tailscale vs Headscale vs NetBird: The Self-Hosted Mesh VPN Decision
WireGuard is the protocol all three products are built on, so "WireGuard vs Tailscale" is the wrong framing. The real question is who runs your control plane: Tailscale's SaaS, a self-hosted Headscale, NetBird's fully open stack, or nobody (raw WireGuard). This guide draws the protocol-vs-control-plane-vs-relay map cleanly, compares the four on the dimensions you actually decide on, explains why kernel and userspace WireGuard perform differently, and gives an infrastructure operator's verdict, including the angle the vendor-written SERP ignores: mesh access into management and out-of-band networks.
Networking
Read more
