Jesse Schokker is the co-founder and Chief Technology Officer of Serverside.com, where he leads the engineering behind the company's bare-metal cloud, from the ASN 55285 backbone and always-on DDoS mitigation to the core automation that drives day-to-day operation.
He also serves as Head of Infrastructure Operations at Host Havoc, a global game-server hosting provider, where he runs the worldwide fleet that keeps latency low and uptime high for players.
Across more than a decade he has founded and run infrastructure and software businesses, working hands-on as a network and software engineer. He writes here about dedicated servers, operating systems, networking, and running production workloads on bare metal.
Areas of expertise
- Bare-metal and IaaS infrastructure
- Network engineering, IP transit and peering
- DDoS mitigation
- Game-server hosting at global scale
- Software engineering (C++ and full-stack)
Articles by Jesse Schokker

04 September 2026
by Jesse Schokker
NetworkManager Crash Course: nmcli and Keyfiles for RHEL Servers
NetworkManager is the daemon that configures the network on every RHEL-family server, and since RHEL dropped the old network-scripts it is the only supported way to do it. This crash course runs it the way a dedicated server uses it: headless, static, over SSH, with nmcli and keyfiles instead of a desktop applet. You will learn the device-and-profile model that clears up most nmcli confusion, a full static IPv4 and IPv6 setup you can paste and adapt, where profiles live on disk across RHEL 8, 9, and 10, and how to change the network on a remote box without locking yourself out.
Linux
Read more

02 September 2026
by Jesse Schokker
Netplan Crash Course for Ubuntu Dedicated Servers
Netplan is the YAML layer that configures networking on Ubuntu Server: you describe addresses, routes and DNS in one file, and a generator renders that into config for systemd-networkd. This crash course is written for a dedicated box with a static public IP, no Wi-Fi, and SSH as the only way in. It covers where the files live, the root-only 600 permission rule, a full static IPv4 and IPv6 example, the generate, try and apply commands that stop you locking yourself out, plus VLANs, bonds, bridges, and the cloud-init file that keeps overwriting people's edits.
Linux
Read more

28 August 2026
by Jesse Schokker
Running OPNsense as a Firewall VM on Proxmox
A virtualised OPNsense firewall on your Proxmox host gets you what appliance vendors charge four figures for: a full-featured firewall/router guarding your VMs, with snapshots before every upgrade and no extra hardware. The catch is that the setup details (bridges, VirtIO, offloading) decide whether it's rock-solid or mysteriously flaky. This guide covers the network designs that work on a dedicated server, the exact VM configuration the community has converged on, the install, and the honest caveats about performance and protecting the Proxmox host itself.
Networking
Read more

26 August 2026
by Jesse Schokker
Proxmox VE vs XCP-ng: Choosing an Open-Source Hypervisor
Post-VMware shortlists usually come down to these two: Proxmox VE, the Debian/KVM platform with everything integrated, and XCP-ng, the Xen-based XenServer descendant managed through Xen Orchestra. Both are genuinely production-grade and genuinely free; they just embody different philosophies about how a virtualisation platform should be built. This comparison covers the architectural split (KVM-in-Linux vs Xen-plus-dom0), the very different management and support models, storage and backup stories, current pricing on both sides, and a conditions-based verdict.
Virtualization
Read more

21 August 2026
by Jesse Schokker
Ubuntu Server in 2026: Choosing Between LTS Releases (and Upgrading)
Three Ubuntu LTS releases are in service right now: 22.04 approaching the end of standard support, 24.04 in its comfortable middle years, and the new 26.04 "Resolute Raccoon" with Linux 7.0. Which one belongs on your server depends on where you are in the cycle, and the answer is different for new deploys and existing fleets. This guide gives the support-window table, what actually changed in 26.04 for server operators, the honest reasons to stay on 24.04 for now, and the upgrade mechanics, including when the LTS-to-LTS path opens after 26.04.1.
Linux
Read more

17 August 2026
by Jesse Schokker
Ubuntu vs Debian for a Dedicated Server: How to Choose
Ubuntu is built from Debian, so this is a comparison between close relatives: same package format, same init system, largely the same administration. The real differences are cadence, support windows, kernel freshness, and who stands behind the updates: a fixed two-year LTS rhythm with optional paid coverage to 2036, versus a community release that's done when it's done and free forever. This guide lays out what the two actually share, where they genuinely differ, and which server workloads favour which, with current versions and support dates, not folklore.
Linux
Read more

14 August 2026
by Jesse Schokker
Bare Metal vs Dedicated Server: What the Two Terms Actually Mean
Bare metal and dedicated server describe the same thing: one physical machine, rented whole, with no hypervisor and no other tenant on it. The confusion is not about the hardware. It is about which era of hosting vocabulary a provider is using, and that vocabulary tends to predict how the machine is sold to you: by ticket or by API, by the month or by the hour. This guide explains where each term came from, lays out the operating-model differences a provider's word choice usually signals, gives you five questions to ask before you order, and covers the one case where neither term is what you actually want.
Infrastructure
Read more

14 August 2026
by Jesse Schokker
CentOS Alternatives in 2026: AlmaLinux vs Rocky Linux (and How to Migrate)
CentOS Linux is gone (CentOS 8 reached end of life at the end of 2021 and CentOS 7 followed in mid-2024), and CentOS Stream is not a like-for-like replacement. The two real successors are AlmaLinux and Rocky Linux, and since 2023 they no longer work the same way under the hood: AlmaLinux targets ABI compatibility with RHEL, Rocky holds 1:1 binary parity. This guide explains what actually differs between them now, gives a conditions-based verdict instead of "it depends," and walks the real migration paths (migrate2rocky, almalinux-deploy, and ELevate for the CentOS 7 cross-major jump), including the pre-flight checklist, the inhibitor wall, and the rollback plan.
Linux
Read more

12 August 2026
by Jesse Schokker
Self-Hosting Headscale on a Dedicated Server: Step-by-Step
Headscale gives you the half of Tailscale that isn't open source: the coordination server. Run it yourself and the official Tailscale clients (with their excellent NAT traversal and platform support) connect to infrastructure you control, with no per-user pricing and no third party holding your network's keys. This guide is the practical walkthrough: install from the official packages, TLS done the simple way, users and ACLs, the embedded DERP relay on your own network, and the honest operational limits of a deliberately small project.
Networking
Read more

10 August 2026
by Jesse Schokker
LXC Containers vs KVM VMs in Proxmox: When to Use Which
Proxmox VE gives you two ways to slice a server: full virtual machines via KVM, and LXC system containers that share the host's kernel. The right choice per workload is usually clear once you know the three questions that decide it: isolation, kernel, and migration. This guide explains how each actually works, compares them on the dimensions that matter operationally, settles the Docker question with Proxmox's own current guidance, and ends with a decision table you can apply per service.
Virtualization
Read more

07 August 2026
by Jesse Schokker
How to Upgrade Debian 12 to Debian 13 on a Production Server
Debian 12 "bookworm" quietly crossed a line in June 2026: regular security support ended, and it now runs on LTS. Debian 13 "trixie" has meanwhile matured through seven point releases, which makes this the right moment to do the in-place upgrade. This guide covers the full procedure for a remote production server: the pre-flight checklist (including the interface-renaming trap that can cut a remote box off mid-upgrade), the three-command upgrade itself, and the trixie-specific changes to check afterwards: /tmp on tmpfs, the sysctl move, and OpenSSH 10.
Linux
Read more

05 August 2026
by Jesse Schokker
How to Capture and Analyse a DDoS Attack with Wireshark (and tcpdump)
When your server is under attack, "we're being DDoSed" is not actionable; "SYN flood, four million packets per second, spoofed sources, targeting port 443" is. The difference between the two is a thirty-second packet capture and a structured look at it. This guide covers capturing safely on a machine that's already saturated (tcpdump, not the Wireshark GUI), the triage workflow in Wireshark (Protocol Hierarchy, Conversations, I/O Graphs) and the display-filter signatures of the common attack vectors, ending with how to turn findings into mitigation.
Security
Read more

03 August 2026
by Jesse Schokker
Building a Proxmox Cluster with High Availability on Dedicated Servers
A Proxmox cluster's honest requirements fit in one sentence: three nodes, a low-latency private link between them, and storage the surviving nodes can reach. Everything else (quorum, fencing, Ceph versus replication) is the reasoning behind those three. This guide covers what clustering gives you before HA even enters the picture, why quorum makes three the magic number, the corosync network rules people violate first, the three storage strategies, and what a failover actually looks like when a node dies at 3 a.m.
Virtualization
Read more

29 July 2026
by Jesse Schokker
WireGuard vs Tailscale vs Headscale vs NetBird: The Self-Hosted Mesh VPN Decision
WireGuard is the protocol all three products are built on, so "WireGuard vs Tailscale" is the wrong framing. The real question is who runs your control plane: Tailscale's SaaS, a self-hosted Headscale, NetBird's fully open stack, or nobody (raw WireGuard). This guide draws the protocol-vs-control-plane-vs-relay map cleanly, compares the four on the dimensions you actually decide on, explains why kernel and userspace WireGuard perform differently, and gives an infrastructure operator's verdict, including the angle the vendor-written SERP ignores: mesh access into management and out-of-band networks.
Networking
Read more

27 July 2026
by Jesse Schokker
Proxmox VE Networking Explained: Bridges, Bonds and VLANs
Networking is where most new Proxmox installations stall: the install works, the first VM boots, and then "how do I give it an IP?" turns into an afternoon of half-matching forum threads. The underlying model is actually small: VMs plug into Linux bridges, and everything else is variations. This guide builds that model properly: what vmbr0 really is, bridged versus routed versus NAT setups on a hosting provider, VLAN-aware bridges, bonding done right, where the SDN layer fits, and how to change any of it without cutting yourself off.
Virtualization
Read more

22 July 2026
by Jesse Schokker
iptables vs nftables: What Changed and How to Migrate
If your server runs a current Debian, Ubuntu, or RHEL-family distro, your "iptables" rules are almost certainly already executing inside nftables. The iptables command has been a compatibility shim since 2019. The real question isn't which one wins; it's whether to keep writing rules in a legacy syntax on top of the new engine. This guide covers what actually changed architecturally, a side-by-side syntax comparison, what the honest performance data says, and a migration path that won't break Docker or lock you out.
Security
Read more

20 July 2026
by Jesse Schokker
How to Set Up Your Own Proxmox VE Server
You have a bare-metal box and you want it to run virtual machines and containers instead of a single operating system. Proxmox VE turns that raw hardware into a full virtualisation platform: a Debian-based host with a web UI, KVM full virtualisation, LXC system containers, built-in storage and networking, and no per-socket hypervisor licence to buy. This guide walks the whole path from a blank server to a working host. We install Proxmox VE 9.2 from the ISO, fix the APT repositories and update, understand the default bridge networking, look at storage, build a first VM and a first LXC container, and finish with basic hardening. By the end you will have a production-ready single node you can grow into a cluster later.
Virtualization
Read more

17 July 2026
by Jesse Schokker
DDoS Attacks Explained: Common Forms and How to Protect Against Them
DDoS attacks come in three broad families: volumetric floods that saturate your pipe, protocol attacks that exhaust connection state, and application-layer floods that look like legitimate traffic. Each one exhausts a different resource, so each one needs a different defence, and no single layer stops all three. This guide maps the common attack forms to the resource they target and the mitigation that actually works against them, explains what an on-host firewall can and cannot stop, and ends with a practical incident-response runbook for when your server is under fire.
Security
Read more

15 July 2026
by Jesse Schokker
First Hour on a New Linux Dedicated Server: A Hardening Checklist
A freshly provisioned server starts receiving SSH probes within minutes of its IP going live; honeypot studies show most exposed machines are attacked within a day. The good news: the defences that matter are a short, boring, one-hour checklist, not a security research project. This guide walks the eight steps in order (users and SSH keys, firewall baseline, automatic updates, fail2ban, time sync, a listener audit, and logging) with the exact commands for Debian/Ubuntu and the RHEL family, plus an honest list of what not to waste your first hour on.
Linux
Read more

13 July 2026
by Jesse Schokker
Proxmox Backup Strategies: Snapshots, vzdump and Proxmox Backup Server
Proxmox VE ships everything you need to never lose a VM, and the defaults use almost none of it. Snapshots that live on the same disk as the VM, one-off vzdump archives with no retention plan, and no restore testing is how virtualisation hosts actually get hurt. This guide builds the real strategy in three tiers: what snapshots are actually for, scheduled vzdump done properly (modes, retention, fleecing), and when Proxmox Backup Server's deduplication, verification, and offsite sync become worth a second box.
Virtualization
Read more

08 July 2026
by Jesse Schokker
Sensible Default Firewall Rules for a Linux Server
A fresh Linux server ships with no firewall rules at all. Every listener you start is instantly reachable from the whole internet. The fix is a short, well-understood baseline: default-deny inbound, allow established traffic, and an explicit allow-list for the services you actually run. This guide builds that baseline in nftables rule by rule, explains the parts everyone gets wrong (ICMP and IPv6), shows the same policy in ufw and firewalld, and covers how not to lock yourself out, plus the Docker port-publishing trap.
Security
Read more

08 July 2026
by Jesse Schokker
What Is Proxmox VE? Choosing a Bare-Metal Hypervisor
Proxmox VE is a free, open-source virtualisation platform that runs directly on a physical server, turning one machine into a host for full virtual machines and lightweight containers. But it is not the only bare-metal hypervisor: VMware ESXi, XCP-ng, and Hyper-V all solve the same problem differently, and the right choice depends far more on licensing, clustering, and your team's ecosystem than on raw features. This guide explains what Proxmox VE actually is, what a bare-metal hypervisor means, and how the four main contenders compare on cost, management, high availability, storage, and backup, with a side-by-side table, an opinionated decision framework, and links to the right server to deploy it on.
Virtualization
Read more

06 July 2026
by Jesse Schokker
Linux Dedicated Servers: How to Choose the Right Distribution
A Linux dedicated server gives you a whole physical machine with no hypervisor in the way, but which distribution should you run on it? Ubuntu, Debian, the CentOS successors, and RHEL each make different trade-offs around release cadence, support, and cost. This guide explains what a bare-metal Linux server actually is, when it beats a VPS or cloud instance, and how to pick a distribution by workload and support needs, with a side-by-side comparison and links to the right server for each.
Linux
Read more
