Server & Storage

Linux Server Management Basics: Beginner Guide for Enterprise Environments

9 min read 1 August 2025

Why Is Linux the Choice for Enterprise Servers?

The majority of the world's largest data centers and cloud infrastructures run on Linux. Its open-source licensing model, high stability, robust security architecture, and broad ecosystem support make Linux indispensable for enterprise environments. This guide systematically covers fundamental administration skills using Ubuntu Server (LTS) and AlmaLinux/Rocky Linux (RHEL-compatible) distributions.

Distribution Selection: Ubuntu Server vs. RHEL-Based

CriterionUbuntu Server LTSAlmaLinux / Rocky Linux
Support period5 years (10 years ESM)10 years
Package managerapt / dpkgdnf / rpm
EcosystemWide, developer-friendlyEnterprise-grade, RHEL-compatible
Free?YesYes
Typical useWeb servers, cloud, containersFinance, healthcare, traditional enterprise

Mandatory Steps After Initial Installation

System Update

# Ubuntu
sudo apt update && sudo apt upgrade -y

# AlmaLinux / Rocky
sudo dnf update -y

Hostname and Timezone Configuration

sudo hostnamectl set-hostname sunucu01.sirket.local
sudo timedatectl set-timezone Europe/Istanbul
timedatectl status

Static IP Configuration (Ubuntu - Netplan)

# /etc/netplan/00-installer-config.yaml
network:
  version: 2
  ethernets:
    ens3:
      addresses: [192.168.1.10/24]
      routes:
        - to: default
          via: 192.168.1.1
      nameservers:
        addresses: [8.8.8.8, 8.8.4.4]
sudo netplan apply

SSH Hardening

SSH is the primary method of remote administration and, if not properly configured, becomes a target for attacks.

Key-Based Authentication

# İstemci tarafında anahtar oluşturma
ssh-keygen -t ed25519 -C "yonetici@sirket.com"

# Public key'i sunucuya kopyalama
ssh-copy-id -i ~/.ssh/id_ed25519.pub kullanici@192.168.1.10

/etc/ssh/sshd_config Security Settings

Port 2222                    # Varsayılan portu değiştirin
PermitRootLogin no           # Root ile doğrudan giriş kapatın
PasswordAuthentication no    # Parola girişini kapatın
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
AllowUsers yonetici deploy
sudo systemctl restart sshd

User and Permission Management

# Yeni sistem yöneticisi oluşturma
sudo useradd -m -s /bin/bash -G sudo yonetici2

# Parola belirleme
sudo passwd yonetici2

# Sudo yetkilerini kısıtlama (örnek: yalnızca servis yönetimi)
sudo visudo -f /etc/sudoers.d/yonetici2
# İçerik: yonetici2 ALL=(ALL) NOPASSWD: /usr/bin/systemctl

Basic System Monitoring Commands

CommandDescription
top / htopDisplays CPU and RAM usage in real time
df -hDisk usage (human-readable)
du -sh /var/*Disk usage by directory
free -mMemory status (MB)
ss -tulpnListening ports and processes
journalctl -xeRecent system log entries
vmstat 1 5Instant CPU, memory, I/O report

Log Management

# Son 100 satır sistem log
journalctl -n 100

# Belirli bir servisin logları
journalctl -u nginx --since "1 hour ago"

# Logları diske yazma (persistent)
sudo mkdir -p /var/log/journal
sudo systemctl restart systemd-journald

Firewall Configuration (UFW / firewalld)

Ubuntu — UFW

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 2222/tcp    # SSH (değiştirilen port)
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

AlmaLinux — firewalld

sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

Automatic Security Updates

# Ubuntu — unattended-upgrades
sudo apt install unattended-upgrades -y
sudo dpkg-reconfigure --priority=low unattended-upgrades

# AlmaLinux — dnf-automatic
sudo dnf install dnf-automatic -y
sudo systemctl enable --now dnf-automatic.timer

Brute Force Protection with Fail2Ban

sudo apt install fail2ban -y   # Ubuntu

# /etc/fail2ban/jail.local
[sshd]
enabled = true
port = 2222
maxretry = 5
bantime = 3600
findtime = 600
sudo systemctl enable --now fail2ban
sudo fail2ban-client status sshd

Disk and RAID Management

# Disk listesi
lsblk -o NAME,SIZE,TYPE,MOUNTPOINT

# Dosya sistemi oluşturma
sudo mkfs.ext4 /dev/sdb1

# /etc/fstab'a kalıcı bağlama
UUID=$(blkid -s UUID -o value /dev/sdb1)
echo "UUID=$UUID /data ext4 defaults 0 2" | sudo tee -a /etc/fstab
sudo mount -a

Conclusion

Linux server administration should be approached as a whole, encompassing SSH security, user authorization, daily maintenance habits, and monitoring tools. When the foundational steps are correctly implemented, server stability and security improve significantly. NRC Sistem provides Linux-based server installation, hardening, and remote management services, supporting your organization in building a professionally configured infrastructure.

All posts