A practical guide to running Linux servers in Azure, AWS, and Google Cloud: creating them, configuring them, operating them day to day, and fixing them when they break. Every topic is explained in plain language and shown with real commands and example output, so you can follow it even if you have never used Linux before.
- Create a Linux VM on Azure, AWS, or Google Cloud from the CLI, with secure defaults
- Connect with SSH, and recover access when SSH fails
- Manage users, permissions, packages, services, scheduled jobs, and logs
- Add, mount, and grow disks, including LVM
- Diagnose network, DNS, firewall, and performance problems layer by layer
- Harden a server and keep it patched
- Automate first-boot setup with cloud-init and routine work with Bash
- Follow runbooks for patching, backups, onboarding, and decommissioning
- Beginners moving into cloud, DevOps, or infrastructure roles
- Windows or EUC engineers who now look after Linux VMs
- Anyone who wants one place to look things up while working on a Linux server
No prior Linux knowledge is needed. Start at Chapter 01 and work in order. If you already know the basics, use the task map below to jump to what you need.
| # | Chapter | You will learn |
|---|---|---|
| 01 | Linux Fundamentals | Kernel, shell, distributions, identifying any server, getting help |
| 02 | Lab Setup | WSL 2, Multipass, Docker, cloud VMs, SSH on Windows |
| 03 | Files and Navigation | Directory layout, paths, copying, redirection, pipes, variables |
| 04 | Reading and Searching Text | less, tail -f, grep, find, awk, sed, tar |
| 05 | Editing Files | nano, vim, safe edits with backup and validation |
| 06 | Users, Groups, and sudo | Accounts, SSH access for users, sudo rules, service accounts |
| 07 | Permissions and Ownership | chmod, chown, special bits, ACLs, fixing "Permission denied" |
| 08 | Package Management | apt and dnf, security updates, automatic updates, repositories |
| 09 | Processes and Services | ps, signals, systemctl, writing a systemd service |
| 10 | Scheduling Jobs | cron, systemd timers, at |
| 11 | Logs | journalctl, /var/log, dmesg, logrotate |
| # | Chapter | You will learn |
|---|---|---|
| 12 | Storage and Filesystems | Data disks, fstab, growing disks, LVM, swap |
| 13 | Networking | IPs, routes, DNS, ss, curl, nc, firewalls, tcpdump |
| 14 | SSH | Keys, config file, scp/rsync, jump hosts, hardening, troubleshooting |
| 15 | Security Hardening | Baseline checklist, fail2ban, SELinux, AppArmor, auditd, Lynis |
| 16 | Bash Scripting | Variables, conditions, loops, functions, safe scripts, examples |
| 17 | Performance and Monitoring | Load, CPU, memory, disk I/O, OOM, sar, cloud limits |
| 18 | cloud-init and Metadata | First-boot automation, instance metadata, VM identities |
| # | Chapter | You will learn |
|---|---|---|
| 19 | Linux on Azure | Create, connect, disks, resize, Run Command, Serial Console, clean up |
| 20 | Linux on AWS | Launch, EBS on NVMe, IAM roles, Session Manager, Serial Console, rescue |
| 21 | Linux on Google Cloud | Create, OS Login, IAP, disks, serial console, clean up |
| # | Chapter | You will learn |
|---|---|---|
| 22 | Troubleshooting | A method and a playbook for the most common failures |
| 23 | Operations Runbooks | Build, patch, onboard, extend disks, HTTPS, backup, decommission |
| 24 | Capstone Project | Build and operate a production-style server, then break and fix it |
Quick reference: CHEATSHEET.md
| I need to... | Go to |
|---|---|
| Create a Linux VM in Azure / AWS / GCP | 19, 20, 21 |
| Fix "I cannot SSH to the server" | 22: Cannot connect with SSH |
| Add and mount a new data disk | 12: Add a data disk |
| Grow a full disk | 23: Extend a disk |
| Recover a VM stuck at boot after an fstab edit | 22: fstab boot failure |
| Patch a server safely | 23: Patch a server |
| Run my application as a service | 09: Write your own service |
| Give a colleague access | 23: Onboard a user |
| Find out why the server is slow | 17: The first 60 seconds |
| Fix "Permission denied" | 07: Method |
| Configure a VM automatically at creation | 18: cloud-init |
- Examples use Ubuntu 24.04 LTS. Where the Red Hat family (RHEL, Rocky, AlmaLinux, Amazon Linux 2023) differs, both commands are shown.
- Code blocks labelled
bashare commands to run. Blocks labelledtextare example output. Your values (IP addresses, sizes, names, dates) will differ. sudois shown wherever a command needs administrator rights.- Cloud CLI examples use Bash line continuation (
\). In PowerShell, replace the trailing\with a backtick (`). - Placeholders are written like
<server-ip>or in capitals likeRG. Replace them with your own values.
- Chapters 01 to 11 and 16 work on any Linux shell: WSL 2 on Windows, Multipass, a container, or a small VM.
- Chapters 12 to 15 and 17 to 24 need a real VM. A small cloud VM (Azure
Standard_B2s, AWSt3.micro, GCPe2-small) is enough. - Cloud resources cost money while they exist. Every cloud chapter ends with a Clean up section. Run it when you finish, and check your billing page.
- Never open SSH to
0.0.0.0/0. The labs show how to allow only your own IP address.
- The Linux commands and labs in Chapters 01 to 17 and 22 to 23 were run on Ubuntu 24.04 LTS with systemd, and the example output was compared with the real output. Problems found during testing were fixed in the text. The exceptions are LVM logical volumes, XFS mounts and
auditd, which the test machine's kernel did not support; their syntax was checked against the man pages. - The example scripts in Chapter 16 pass
shellcheckand were run on Ubuntu 24.04. - The cloud-config in Chapter 18 passes
cloud-init schemavalidation. - Every
azandawscommand was checked against the current Azure CLI and AWS CLI, including the extensions the guide uses, so options and syntax are correct. gcloudcommands and Red Hat family commands were checked against the official documentation but not run for this release.
Cloud providers change their CLIs and defaults over time. If a command no longer works, check the provider's current documentation and open an issue.
Practise on lab machines. Commands that delete data, reformat disks, change firewall rules, or edit SSH and sudo configuration are marked with warnings. On real servers, follow your organisation's change process and have a rollback plan and console access ready before you start.
