A production server is a network endpoint under constant automated scanning from the internet. At Swiggy and Razorpay, every server follows a security baseline: SSH keys only, firewall default-deny, fail2ban blocking brute force, and kernel hardening applied from day one. This pillar covers both the diagnostic tools that find network problems fast and the hardening practices that prevent them.
What This Pillar Covers
- Configuring SSH securely — Ed25519 keys, ~/.ssh/config for bastion access, and sshd_config hardening
- Diagnosing network failures with ip, ss, dig, curl, mtr, and tcpdump
- Building iptables and ufw firewall rulesets with default-deny and correct rule ordering
- Applying a production security hardening baseline — fail2ban, sysctl parameters, and lynis compliance auditing
Who This Is For
DevOps engineers, platform engineers, and security-conscious developers who need to operate Linux servers securely and diagnose network connectivity failures under pressure.
Why This Matters in Production
At Razorpay, an exposed PostgreSQL port on a misconfigured server was discovered by automated scanners within 4 minutes of provisioning. A properly configured firewall with default-deny makes the port invisible — not just closed, but completely unresponsive to external probes.
Prerequisites
- Linux Fundamentals and Process Management
- Basic understanding of TCP/IP, DNS, and HTTP
- Familiarity with what a port number and firewall are