Linux
The SSH Commands I Actually Use Every Day
A practical field guide to SSH: keys, agents, config files, tunneling, jump hosts, and the small commands that quietly make remote work tolerable
I have been using SSH for over twenty years and I still occasionally forget the flag for tunneling. Not because the syntax is hard, but because SSH has so many little features that you only reach for once every few months — and by the time you need them again, your fingers have moved on.
So this post is the field guide I wish I could hand to past-me. Not “how SSH works under the hood” — there are excellent treatises for that. Just the dozen or so commands and config patterns I genuinely reach for during a normal week of operations work.
Securely Deleting Files on Linux and macOS (Beyond shred)
A practical guide to securely erasing files on Linux and macOS — secure-delete, wipe, blkdiscard, hdparm, nvme-cli, and why encryption is the real answer
shred is the tool everyone reaches for, but it’s far from the only one — and on modern SSDs and journaling filesystems, it’s often the wrong one. This post covers the alternatives: secure-delete, wipe, blkdiscard, hdparm, nvme-cli, and the macOS equivalents — plus why full-disk encryption is now the recommended approach for serious data hygiene.
Installing the Vagrant libvirt Provider on Ubuntu 22.04 LTS
End-to-end setup for running Vagrant on top of KVM/libvirt on Ubuntu 22.04 — virtualization packages, group membership, NFS, plugin build dependencies, and the vagrant-libvirt plugin itself
Installing the Vagrant libvirt Provider on Ubuntu 22.04 LTS
Vagrant ships with VirtualBox as its default provider, but on Linux KVM/libvirt is the better fit: it’s the kernel’s native hypervisor, it’s faster, and it doesn’t require an out-of-tree kernel module. The bridge between the two is vagrant-libvirt, a Vagrant plugin that drives libvirt instead of VirtualBox.
This post walks through the full setup on Ubuntu 22.04 LTS (Desktop or Server). It is largely a distillation of Paul Neumann’s gist, which itself builds on Philippe Vanhaesendonck’s Oracle Linux write-up — kept here for my own reference and slightly reorganized.
SSH Hardening: 9 Techniques That Cut 50,000 Monthly Attacks to Almost Zero
Practical SSH hardening guide with nine production-tested techniques to dramatically reduce brute-force attacks and secure your servers
Last January, I sat down to review a server’s auth logs and felt a familiar knot in my stomach.
Over 50,000 failed SSH login attempts — in a single month. Bots methodically hammering port 22 with common credentials, dictionary wordlists, and leaked password databases. Just waiting for one mistake.
That audit changed how I think about SSH security. Not as a checkbox, but as a discipline. What follows are the nine hardening techniques I’ve since applied across dozens of production servers. Not theoretical guidelines — actual configurations with real, measurable outcomes.
My IP from the Internet's view (shell)
Quick shell one-liners to find your public IP address using curl, dig, and a few alternatives — no browser required
Sometimes you just need to know what IP address the rest of the internet sees when your machine reaches out. Maybe you’re configuring a firewall rule, troubleshooting a VPN, or verifying that traffic is actually leaving through the tunnel you think it is.
No need to open a browser. A terminal is enough.